Privacy Policy

Last updated: April 12, 2026

1. Who We Are

EasyOnward ("we," "us," "our") is a travel intelligence platform that helps travelers understand visa, transit, and entry requirements for international travel. This Privacy Policy explains how we collect, use, store, and protect your personal information.

2. Information We Collect

Account Information

When you create an account, we collect your name and email address via your OAuth provider (Google, Apple). We do not collect or store your OAuth provider password.

Traveler Profile Data

To provide personalized travel compliance analysis, you may voluntarily provide:

  • Citizenship(s) and country of residence
  • Passport details (issuing country, expiry date, passport number)
  • Visa and residence permit information
  • Vaccination status (e.g., yellow fever)
  • Date of birth and name (from passport scan)

Passport Scan Data

When you use the passport scan feature, your passport image is uploaded to our server for MRZ (Machine Readable Zone) extraction. The image is processed in memory and is not stored. Only the extracted text fields (name, nationality, expiry, etc.) are saved to your profile.

Usage and Analytics Data

We collect anonymized usage data including search queries, affiliate link clicks, pages visited, and feature usage. This data helps us improve the product and is not linked to your identity unless you are signed in.

3. How We Use Your Information

  • Travel compliance analysis — evaluating visa, transit, and entry requirements based on your profile
  • Personalized recommendations — suggesting which passport to use, applicable waivers, required documents
  • Account management — authentication, saved trips, group travel features
  • Product improvement — understanding which features are used and where users encounter issues
  • Affiliate services — when you click an affiliate link (e.g., onward ticket, travel insurance), we track the click for attribution but do not share your profile data with the affiliate provider

4. How We Protect Your Data

  • Sensitive fields (passport number, date of birth) are encrypted at rest using AES-256 (Fernet) encryption
  • All data in transit is encrypted via TLS
  • Authentication uses secure HttpOnly session cookies — no tokens stored in browser localStorage
  • Database access is restricted and connection-pooled with parameterized queries (no SQL injection)
  • Travel Briefs (shareable compliance reports) contain no PII — only rule explanations and official sources

5. Data Sharing

We do not sell your personal information. We share data only in these limited circumstances:

  • Group travel — if you join a group trip, other members may see limited travel compatibility information (e.g., "this destination has a blocker for one member"). Sensitive details (passport numbers, criminal history, health data) are never shared with group members.
  • Affiliate partners — when you click an affiliate link, the partner receives a tracking ID and the URL you visited. They do not receive your profile data.
  • Legal requirements — we may disclose data if required by law, subpoena, or court order.

6. Data Retention

Your profile data is retained as long as your account is active. You can delete your profile data at any time from the Traveler Profile page. If you delete your account, all associated data (profile, trips, evaluations) is permanently deleted within 30 days.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent for data processing
  • Opt out of analytics tracking

To exercise any of these rights, contact us at privacy@easyonward.com.

8. Cookies

We use a single essential session cookie for authentication. We do not use third-party advertising cookies. Analytics tracking uses server-side event logging, not browser cookies.

9. Children

EasyOnward is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date. Continued use of the platform after changes constitutes acceptance.

11. Contact

For privacy-related questions or requests, contact us at privacy@easyonward.com.

Terms of Use