Skip to main content

Privacy Policy

Last updated 4 August 2026

1. About this policy

VisaPacks is committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what personal information we collect, how we use and store it, and your rights as a user.

VisaPacks is a document organisation tool accessible at visapacks.com.au and, on iOS and Android, as a mobile app. It helps you gather and manage the documents required for an Australian visa application. This policy covers both the website and the mobile app; where their data practices differ, that's noted below.

2. What personal information we collect

2.1 Anonymous users

  • A randomly generated session identifier stored in a browser cookie
  • Your selected visa subclass and questionnaire answers (e.g. relationship status, country of birth, profession — no name or contact details are collected)
  • Documents you upload to your checklist (passport copies, financial statements, and other visa-related files) — on the mobile app, this includes photos you take with your camera or choose from your photo library, in place of a file/browser upload

2.2 Registered accounts

  • Email address
  • Password (stored as a bcrypt hash — your plain-text password is never stored or transmitted)
  • Google Sign-In identifier (only if you choose to sign in with Google — on the mobile app this uses Google's native Sign-In SDK rather than a web redirect, but collects the same identifier)
  • Payment status: a Stripe customer ID (web) or your purchase/entitlement status as managed by RevenueCat (mobile app) — card and payment details themselves are handled entirely by Stripe or the App Store/Google Play, and are never stored by us

2.3 Bug reports (optional)

  • Description of the issue you report via the bug report form
  • Screenshot or attachment (optional, max 5 MB) that you choose to attach
  • Email address (optional) if you wish to receive a follow-up
  • The URL of the page you were on when the issue occurred

2.4 Technical data

  • IP address, used for rate limiting and abuse prevention
  • Browser type and version, used for compatibility diagnostics

2.5 Mobile app specifics

In addition to the above, the mobile app:

  • Records first-party app-activity events (e.g. which screens and tools you use) to understand product usage — this is separate from Google Analytics (section 7) and is never used for advertising
  • Uses RevenueCat to manage and verify in-app purchases against the App Store/Google Play, as described in section 5
  • Does not collect your device location, use advertising or cross-app tracking identifiers, or include any crash-reporting/diagnostics SDK
  • Schedules local notifications on your own device (e.g. a checklist progress reminder) — these are generated and shown entirely on-device and are not sent from our servers

3. How we use your information

We use your information only to:

  • Provide and operate the VisaPacks checklist and document management service
  • Associate your uploaded files and checklist progress with your session or account
  • Process payments and confirm your access status
  • Send transactional emails — email verification, password reset, and payment receipts. We do not send marketing emails.
  • Detect and prevent abuse, fraud, and unauthorised access
  • Respond to support and privacy enquiries

Advertising conversion measurement (with your consent). If you accept marketing measurement on our cookie banner, we share a limited set of conversion events — for example, that an account was created, a checklist was built, or a purchase was made — with Meta Platforms, using its server-side Conversions API, so we can measure and improve our advertising. This never includes your uploaded documents or which visa subclass you are applying for; only the event itself and hashed contact details (such as your email) used to match the conversion. We do not load the Meta Pixel or any browser advertising cookie. You can decline this at any time from the cookie banner or by contacting us, and it is off unless you opt in. We do not otherwise use your personal information for marketing, and we do not carry out automated profiling that produces legal or similarly significant effects.

4. Storage and security

Your data is stored on secure cloud servers. Uploaded documents are held in access-controlled storage and are never publicly accessible by URL. All file access requires authentication.

We apply industry-standard protections including:

  • HTTPS encryption in transit — all data between your browser and our servers is encrypted using TLS
  • HTTP security headers — we set X-Content-Type-Options, X-Frame-Options: DENY, Content-Security-Policy, and Referrer-Policy on all responses to reduce common web vulnerabilities
  • bcrypt password hashing — your password is never stored in plain text
  • Server-side file access controls — uploaded files are stored with randomised identifiers and are never exposed via predictable URLs
  • CSRF protection — all state-changing requests require a valid CSRF token
  • Rate limiting — login and file upload endpoints are rate-limited to prevent abuse
  • Magic-byte file validation — uploaded files are validated by content signature, not just file extension

Where your files are stored

  • Anonymous and free account uploads: your documents are never uploaded to our servers at all — they're processed only to validate and, where relevant, compress/merge/unlock them, then kept solely in your own browser's local storage. Your checklist and progress (which items you've completed, file names and sizes) are saved to your session or account, but the file contents stay on your device.
  • Paid accounts with Cloud Save off (the default): same as above — your documents stay in your browser's local storage on that device only.
  • Paid accounts with Cloud Save on: your documents are uploaded to our servers and retained until you delete them or close your account, so you can access them from any device you sign in from.
  • Anonymous session metadata: checklist progress for a guest (non-account) session is automatically deleted 24 hours after the session starts.
  • Payment records: retained for 7 years as required under Australian tax law
  • IP and rate-limit logs: retained for up to 30 days

Because browser-local documents never reach our servers, they're only available on the device and browser you uploaded them from, and will be lost if you clear that browser's site data. Turning on Cloud Save (paid accounts only) uploads your existing local documents to our servers and keeps future uploads there too.

5. Third-party service providers

We do not sell or rent your personal information. The only marketing-related sharing is the consented, limited advertising-conversion measurement described in section 3 (with Meta). We use the following service providers who process data on our behalf:

Provider Purpose Privacy policy
Stripe, Inc. Payment processing stripe.com/au/privacy
Google LLC Optional sign-in (web OAuth or the mobile app's native Sign-In SDK); Google Analytics (site usage measurement) policies.google.com/privacy
RevenueCat, Inc. Mobile app in-app purchase management and entitlement verification (App Store/Google Play) revenuecat.com/privacy
Resend, Inc. Transactional email delivery (verification, password reset, receipts) resend.com/legal/privacy-policy
Meta Platforms, Inc. Advertising conversion measurement (server-side Conversions API), only with your consent — limited event data and hashed contact details, never documents or visa subclass facebook.com/privacy/policy

These providers are bound to process your data only as directed by us and in accordance with applicable law. We may also disclose personal information if required by law or a court order, or to protect the rights or safety of our users.

6. Cookies

We use a small number of cookies to operate the service. See our Cookie Policy for full details.

7. Analytics

On the website, we use Google Analytics to understand aggregate site usage (pages viewed, general location, device type). This data is not used to identify you personally. See our Cookie Policy for how to opt out.

Separately, and only if you consent on the cookie banner, we send a limited set of conversion events to Meta server-side (see section 3) to measure our advertising. This is distinct from Google Analytics, carries no documents or visa-subclass data, and can be declined at any time.

The mobile app additionally records first-party app-activity events directly on our own servers (e.g. which screens and tools you use) to understand product usage. This is our own analytics, not a third-party service, and is never used for advertising or shared with anyone outside VisaPacks.

8. Your rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Correct personal information that is inaccurate, incomplete, or out of date
  • Request deletion of your personal information, subject to our legal retention obligations
  • Make a complaint if you believe we have breached the APPs

To exercise any of these rights, contact us with the subject "Privacy Request". We will respond within 30 days.

You may also delete your account at any time from My Account. This immediately deletes all your uploaded documents and anonymises your account data. Note that Stripe payment records cannot be deleted as they are subject to financial record-keeping requirements.

9. Complaints

If you are not satisfied with how we handle a privacy matter, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page. Continued use of VisaPacks after a policy change constitutes acceptance of the updated terms.

11. Contact

For all privacy enquiries: contact us