Trust

Passport data never touches your systems.

The traveler uploads to us, pays us, and we submit to the government. Your integration carries a route and an email address: nothing that shows up in a security review.

No passport data in your stack
Uploads go straight to us. Your integration passes a route and a contact email.
EU hosted
Application data and documents stored in the European Union.
Minimal retention
Documents are deleted once the government decision is final and the retention window closes.
Alliance GDPR member
Independent GDPR framework, plus a public trust center.

Where the data sits

Passport images SimpleVisa, EU · deleted after decision
Traveler identity SimpleVisa · retained per legal obligation
Payment data PCI-compliant processor, tokenised
What you receive Status, reference, fee. No document data
Data controller SimpleVisa for the application, you for the booking

Documents

Trust center
Live security posture and subprocessors
View
Data processing agreement
Standard DPA, signable at signup
View
Security overview
Architecture, access control, incident process
View
Subprocessor list
Updated with 30 days notice
View