ParchiVisa · Legal
Privacy Policy
ParchiVisa collects the answers you give the readiness checker and the profile you build around them, because that is the material the assessment runs on. This policy names every company that touches that data, what each one receives, and how you have it erased.
- Last updated
- Version
- v1.0-draft
Who operates ParchiVisa
ParchiVisa is operated by {{LEGAL_ENTITY_NAME}}, a sole proprietorship registered in Pakistan under FBR National Tax Number {{NTN}}, with its place of business at {{REGISTERED_ADDRESS}}. In this policy, “we” and “us” mean that business, and “you” means the person using the service.
The service is provided at parchivisa.app. Because the operator is established in Pakistan and many of its users are not, please read the section on international transfers — it is the part of this policy most likely to matter to you.
For any question about this policy, or to exercise a right described in it, write to {{PRIVACY_CONTACT_EMAIL}}.
What we collect
We collect three kinds of data: what you give us, what is created when the assessment runs, and what is recorded automatically because the service is a website.
Account data, held so that you have an account to come back to: your email address, your name if you provide one, and the account identifier issued by our authentication provider. We never receive or store your password — see Clerk in the table below.
Visa profile data, which is the substance of what the service does. This is the profile you complete during onboarding and the answers you give the readiness checker: your preferred name, your nationality, the country you are applying from, the countries you are interested in, your study level and intended intake, your admission status, how your studies are funded and your relationship to any sponsor, whether your funds are arranged, the state of your bank statement, whether you have had a previous visa refusal, any study gap, and whether you have dependants.
Several of those fields are sensitive in ordinary language even where they are not “special category” data in a strict legal sense. A previous refusal, a funding source and a nationality are precisely the facts an applicant would not want disclosed. We treat them accordingly.
Assessment data generated as you use the service: your readiness scores and their history, the blockers, warnings and recommendations produced for you, your visa file checklist, your timeline and its milestones, and any Readiness Report you generate.
Financial statement data, if you use the Financial Document Checker. This is the narrow case, and it works deliberately: the statement you supply is processed in memory and is never written to storage. We keep only the values derived from it — balances, account holder name, bank name — together with a SHA-256 hash of the original bytes used for de-duplication. Those derived values are encrypted before they reach the database, as described under Security.
Technical data recorded automatically: IP address, browser and device characteristics, the pages you request, timestamps, and error diagnostics when something breaks. This arrives through our hosting and analytics providers rather than being collected by us directly.
Why we use it, and on what basis
- To run the readiness assessment and produce your score, gap list and action plan — this is the service you asked for, and it cannot be provided without this data.
- To keep your account, your history and your saved visa file available to you between sessions.
- To generate a Readiness Report when you request one, and to make it available to you afterwards.
- To process payment, and to apply or revoke a paid plan when our payment provider notifies us of a sale, refund or chargeback.
- To keep the service working and secure: rate limiting, abuse prevention, error diagnosis, and enforcement of usage limits.
- To understand how the service is used in aggregate, so that it can be improved.
- To meet the legal, tax and accounting obligations that apply to the operator in Pakistan.
Where the UK GDPR or the EU GDPR applies to you, our lawful bases are: performance of a contract, for everything needed to deliver the assessment and maintain your account; legitimate interests, for security, abuse prevention, error reporting and aggregate analytics; consent, for non-essential analytics and session-replay technologies where consent is required; and legal obligation, for tax and accounting records.
We do not sell your personal data. We do not use it to train any machine learning model of our own, and we do not ask any provider to train theirs on it.
Who else processes your data
ParchiVisa is built on third-party infrastructure. The companies below process your data on our behalf, each for the stated purpose. This list is complete as at the version and date shown at the top of this page.
| Provider | What it does | What it receives |
|---|---|---|
| Clerk | Authentication and account management | Your email address, your name if provided, your password — which is set and held by Clerk and never by us — along with account identifiers and session metadata. |
| Vercel | Frontend hosting and content delivery | Every request to parchivisa.app: IP address, user agent, requested URL and timestamps, recorded in request logs. |
| DigitalOcean | Backend hosting on a Coolify-managed droplet, the managed PostgreSQL database, and the Redis cache alongside it | All account, profile, assessment and derived financial data — this is the primary database. Region: {{DO_REGION}}. |
| Cloudflare | DNS for parchivisa.app, and R2 object storage | DNS resolution metadata. R2 holds the visa rules dataset and any Readiness Report PDF you generate; report PDFs are stored privately and released only through short-lived signed links. Jurisdiction: {{R2_JURISDICTION}}. |
| Google — Gemini API | Rewrites the findings in your Readiness Report into readable prose | Per finding: an identifier, a severity, a title, a category, the derived signal describing the specific gap found in your answers, and the official policy text it cites. See the notice below. |
| Google — Analytics 4 | Aggregate usage analytics | IP address, device and browser characteristics, pages visited, and interaction events. |
| Microsoft — Clarity | Session replay and heatmaps | A recording of your interaction with the pages you visit. Assessment inputs and results surfaces are masked at the source, so their contents are excluded from recordings. |
| Sentry | Error and crash reporting | Stack traces, the URL where an error occurred, and browser context. Configured so that request bodies are never attached and report links are redacted, because those bodies hold your answers. |
| Gumroad | Payment processing | Your payment details, which you give to Gumroad directly and which we never see or hold. We receive notification of a sale, refund, dispute or cancellation so that we can set or revoke your plan. |
Two further points about that call. It is optional to the feature — if the model is unavailable or unconfigured, the report is still produced, using our own templated prose. And the model is never permitted to originate a fact: it may only restate findings our engine has already determined, under a schema that rejects anything else.
Anthropic’s Claude API is integrated for two features that are not currently enabled for users: a statement-of-purpose reviewer and a mock interview. While those features remain switched off, nothing is sent to Anthropic. If they are enabled, the text you supply to them will be transmitted to Anthropic, and this policy and its version will be updated before that happens.
We also request currency exchange rates from open.er-api.com in order to estimate proof-of-funds amounts. Only currency codes are sent. No personal data reaches that service.
Separately from the above, we may disclose data where we are legally required to do so, where it is necessary to establish or defend a legal claim, or in order to investigate fraud or abuse of the service.
Security
Traffic to and from ParchiVisa is encrypted in transit using TLS. The database is a managed instance with encryption at rest provided by the host, and access to it is limited to the application.
Above that baseline, the sensitive identifiers derived from bank statements — balances, account holder name, bank name — are encrypted by the application before they are written, using authenticated symmetric encryption with a key held outside the database. A copy of the database, or of a backup, therefore yields ciphertext for those fields rather than readable values. If that key is unavailable, the service refuses to store the data at all rather than falling back to plaintext.
Readiness Report PDFs are stored privately and are reachable only through a signed link that expires. Report URLs carry an unguessable token and are excluded from search engine indexing.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you, and any competent authority, where we are required to do so.
How long we keep it
We keep your account and visa profile data for as long as your account exists. If you stop using ParchiVisa without deleting your account, we retain that data for {{RETENTION_PERIOD}} after your last activity, and then delete or irreversibly anonymise it.
Assessment history, visa files, timelines and generated reports follow the same schedule, and are deleted along with the account.
Derived financial statement data is kept for {{FINANCIAL_RETENTION_PERIOD}} from the date of the check and is then deleted. The statement itself was never stored.
Records of payments and refunds are kept for {{FINANCIAL_RECORDS_RETENTION}} in order to satisfy tax and accounting obligations, and are retained even after an account is deleted. Server and analytics logs are kept for {{LOG_RETENTION_PERIOD}}, on the retention schedule of whichever provider holds them.
Your rights, and how to delete your data
You can ask us to give you a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to provide it in a portable form. Where we rely on your consent, you can withdraw it at any time, without affecting anything done beforehand.
To request deletion, email {{PRIVACY_CONTACT_EMAIL}} from the address on your account, with the word “deletion” in the subject line. We will confirm receipt and complete the deletion within {{DELETION_SLA}}. We may need to verify that the request comes from you, which we will do through the email address on the account rather than by asking you for identity documents.
Deletion removes your account, your profile, your assessment history, your visa files, your timelines and your reports. It does not remove the payment and tax records described above, which we are required to keep, and it does not reach into provider log entries that have already been written and will expire on their own schedule.
Exercising any of these rights is free. If you are in the UK, the EU, Canada or Australia and you believe we have handled your data improperly, you may complain to your data protection authority — in the UK the Information Commissioner’s Office, in Canada the Office of the Privacy Commissioner, in Australia the Office of the Australian Information Commissioner, and in the EU your national supervisory authority. We would rather you raised it with us first, and we will answer.
International transfers
ParchiVisa is operated from Pakistan, and its infrastructure and sub-processors sit outside Pakistan and outside your country. Using the service necessarily involves transferring your data across borders.
If you are in the United Kingdom or the European Economic Area, this matters concretely: Pakistan has not received an adequacy decision from the UK government or the European Commission. Your data is therefore transferred to, and accessible from, a country that is not recognised as providing an equivalent standard of protection. We rely on {{TRANSFER_MECHANISM}} as the safeguard for that transfer, and you may request a copy by writing to {{PRIVACY_CONTACT_EMAIL}}.
If you are in Canada, your data will be processed outside Canada and may be accessible to foreign courts and authorities under the law of the countries where it is held. If you are in Australia, we disclose personal information to overseas recipients in the countries where the sub-processors listed above operate.
In every case the same set of sub-processors applies, and the practical location of your stored data is the region named for DigitalOcean in the table above.
Children
ParchiVisa is intended for people applying to study abroad, and is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to {{PRIVACY_CONTACT_EMAIL}} and we will delete it.
Changes to this policy
When this policy changes, the version identifier and the date at the top of this page change with it. For a change that materially affects how your data is used — a new sub-processor receiving assessment content, for instance — we will tell account holders by email before it takes effect, rather than relying on you to re-read this page.
Privacy Policy · v1.0-draft ·