Back to homepage

Privacy Policy

Last updated: September 21, 2026

This Privacy Policy explains how ESTAFast ("we", "us") collects, uses, discloses, and protects your personal data when you use our ESTA application service, in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection law.

1. Data Controller

ESTAFast acts as the data controller for the personal data collected through this website and application wizard for the purpose of providing the ESTA expediting service.

2. What We Collect

Contact data: email address, phone number.

Identity and passport data: full name, gender, date of birth, city and country of birth, passport number, passport issue and expiry dates, nationality.

Travel data: parents' names, home address and city, and the hotel name or contact person for your first stay in the US, as required by CBP.

Security interview responses: your answers to the ESTA eligibility questions.

Payment data: processed directly by our payment provider, Stripe; we do not store full card numbers on our servers.

Technical data: IP address, browser and device information, and session/language cookies, used for security, fraud prevention, and site functionality.

3. Why We Process Your Data

Performance of a contract (Art. 6(1)(b) GDPR): to prepare, verify, and submit your ESTA application, process payment, and deliver the result to you. This processing is necessary to provide the Service; without it, we cannot submit your application.

Legal obligation (Art. 6(1)(c) GDPR): to meet accounting, tax, and record-keeping obligations.

Legitimate interest (Art. 6(1)(f) GDPR): to prevent fraud, secure our systems, and provide customer support, balanced against your rights and interests.

Consent (Art. 6(1)(a) GDPR): where you explicitly opt in, for example to receive marketing communications. Consent is never required to use the core Service.

4. Who We Share Data With

We do not sell your personal data. We share it only where necessary to provide the Service:

U.S. Customs and Border Protection (CBP): the passport, biographic, and travel data you provide is transmitted to CBP's official ESTA system, as CBP is the government authority that decides your travel authorization. This transfer is required to deliver the Service you request.

Stripe, Inc.: our payment processor, which receives the payment details necessary to process your charge under its own privacy policy and as our data processor.

Hosting and infrastructure providers: process data only on our documented instructions, under data processing agreements, and solely to operate the Service.

In this development build, application data is stored only in a temporary in-memory store on our servers and is not persisted to a production database or shared beyond what is described above.

5. International Data Transfers

Because ESTA applications are submitted to CBP, your data is transferred to and processed in the United States, a country that has not been recognized as providing an adequate level of data protection under GDPR. This transfer is necessary for the performance of the contract you request (Art. 49(1)(b) GDPR): we cannot provide the ESTA application service without transmitting your data to CBP.

Where we transfer data to processors such as our payment provider or infrastructure providers outside the EEA, we rely on Standard Contractual Clauses or another safeguard recognized under GDPR.

6. Data Retention

We retain your application data, including passport and travel information, for as long as necessary to provide the Service and to meet our legal, accounting, tax, and anti-fraud obligations, and in any event no longer than five (5) years after your application is completed, unless a longer period is required by law or an active dispute requires longer retention. Payment records are retained for the period required by Stripe and applicable financial regulations.

7. Your Rights Under GDPR

If you are located in the EU/EEA, UK, or another jurisdiction with equivalent protections, you have the right to: access a copy of the personal data we hold about you; rectify inaccurate or incomplete data; request erasure of your data, subject to our legal retention obligations (for example, we may not be able to delete a submitted application record while a legal retention period applies); restrict processing in certain circumstances; receive your data in a structured, machine-readable format and have it transmitted to another controller (data portability); object to processing based on our legitimate interest; and withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

To exercise these rights, contact us at the support address in your confirmation email. We will respond within one month, as required by GDPR.

You also have the right to lodge a complaint with your local data protection authority. In Poland, this is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, UODO).

8. Security

We use industry-standard technical and organizational measures, including 256-bit encryption in transit, to protect your data against unauthorized access, alteration, disclosure, or destruction. No system is completely secure, and we cannot guarantee absolute security.

9. Cookies

We use only essential session and language-preference cookies required for the application wizard to function. We do not currently use third-party advertising or tracking cookies.

10. Children

The Service is not directed at children. ESTA applications for a minor must be submitted by a parent, legal guardian, or other authorized adult on the minor's behalf.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date.

12. Contact

Questions about this Privacy Policy or requests to exercise your data protection rights can be directed to our support channel referenced in your confirmation email.