PRIVACY POLICY

Passport Reports Privacy Policy and Personal Data Protection

Passport Reports — Web, Android and iOS/iPadOS

Effective date: 5 August 2026

Last updated: 10 August 2026

SCOPE OF THIS POLICY

Passport Reports respects the privacy and security of personal data. This Privacy Policy explains how personal data is collected, used, shared, protected, retained and deleted across the passportreports.com domain and its different language versions, the Passport Reports Android app, the Passport Reports iOS/iPadOS apps, the Passport Reports artificial intelligence assistant and related digital services.

In this document, the website, Android app, Apple apps and all related features are collectively referred to as the “Services”.

This Policy applies whether you access the Services through an internet browser or a secure in-app web view. The Google Play Data Safety and Apple App Privacy disclosures are store-appropriate summaries of the practices described in this Policy and are kept consistent with the Services’ actual data-processing practices.

DATA CONTROLLER AND CONTACT DETAILS

Passport Reports is the controller of the personal data covered by this Policy and the operator of the Services.

Postal address: 1 Seneca St, Buffalo, NY 14203, United States

Email: info@passportreports.com

Telephone: +1 (716) 414-2228

You may send requests concerning privacy, data access, correction, deletion, objection or other data-subject rights to info@passportreports.com with the subject line “Privacy Request”.

INDEPENDENT STATUS OF PASSPORT REPORTS

Passport Reports is an independent information platform providing passport rankings, mobility scores, visa-free travel information, visa on arrival information, electronic travel authorisation information, visa requirements, country reports and global mobility comparisons.

Passport Reports is not operated by any government, ministry, immigration or border authority, embassy, consulate, diplomatic mission, international organisation or official visa centre. It is not an official website or app affiliated with, authorised by or endorsed by any such institution.

The country, passport and travel information provided through the Services is intended for general information, research and comparison. Users should verify current requirements with the relevant country’s authorised official bodies before making travel decisions.

OUR PRIVACY PRINCIPLES

We process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.

We aim not to request sensitive device permissions that are unnecessary for the Services to operate, to use personal data only for the stated purposes and not to use identifiable data where anonymous or aggregated data is sufficient.

DATA THAT MAY BE PROCESSED

Depending on the feature and platform used, the following categories of data may be processed.

Technical and network data: IP address, request time, address visited, referring page, HTTP response information, browser or WebView type, operating system, device class, screen characteristics, language, time zone, connection type, app version, performance information and basic error information.

Approximate location: country-, region- or city-level approximate location derived from the IP address. Passport Reports does not request GPS-based precise location.

Usage and measurement data: page views, session duration, scrolling, clicks, searches, selected country or passport, feature used, referral or campaign parameters, and error and performance events.

Pseudonymous identifiers: first-party cookie identifiers, analytics client identifiers, session identifiers and similar random identifiers.

Artificial intelligence assistant data: the question you enter, the selected language, limited context from the page where the question is asked, secure session information, the generated response and error status.

Communication data: your name, email address, telephone number, organisation details, message, data-correction suggestion, support request and attachments when you voluntarily provide them by email.

Privacy and legal records: data-subject requests, limited information used to verify a request, responses provided, consent or preference records, objections and required legal correspondence.

App-store information: aggregated download, country, app version, performance and store-review information made available to Passport Reports by Google Play or the Apple App Store.

An IP address may be treated as personal data in some countries even though it does not directly reveal your name.

ARTIFICIAL INTELLIGENCE ASSISTANT

The Passport Reports artificial intelligence assistant operates only at the user’s request. The assistant processes the question you enter and the limited page context needed to understand it.

Questions may first be sent to a Passport Reports server and, where necessary, may be classified or answered by a contracted artificial intelligence service provider.

You should not enter a passport number, identity document, date of birth, home address, password, payment information, health information or any other sensitive personal data into the assistant.

Choosing not to use the artificial intelligence assistant does not prevent you from accessing Passport Reports’ core passport-ranking, country-report or travel-information pages.

DATA WE DO NOT INTENTIONALLY COLLECT

The current functions of Passport Reports do not require users to create an account or sign in. Passport Reports therefore does not create user passwords or account profiles.

Passport Reports does not request and does not intentionally seek to collect the following data:

Passport number or a copy of a passport.

National identification number or identity document.

Facial geometry, fingerprints or other biometric data.

GPS-based precise location.

Contacts, SMS messages, call logs or calendar data.

Access to the microphone, camera or continuous photo library.

Health, fitness or medical records.

Bank-account, credit-card or payment information.

Android advertising ID, IMEI, device serial number or Apple IDFA.

Advertising profiles combined with behaviour on other companies’ apps and websites.

If you voluntarily submit sensitive data, it will be processed only to the extent necessary to assess your message, maintain security, comply with a legal obligation or securely delete the data.

PURPOSES OF PROCESSING

Personal data may be processed for the following purposes:

To open the website and apps, load content and operate requested features.

To provide passport search, country selection, comparison, ranking, language and regional functions.

To answer the user’s question through the artificial intelligence assistant.

To measure use of the Services, understand visitor numbers, identify errors and improve features.

To prevent cyberattacks, unauthorised access, automated abuse, spam and fraud.

To maintain the security, performance and continuity of the Services.

To respond to support, data-correction, press, advertising or general communication requests.

To manage privacy preferences and data-subject requests.

To comply with legal obligations, exercise legal rights and manage disputes.

To produce anonymous or aggregated statistics concerning use of the Services.

LEGAL BASES FOR PROCESSING

Depending on the processing activity, data is processed on one or more of the following legal bases:

Providing a service requested by the user or performing a contract.

Taking pre-contractual steps at the user’s request.

Our legitimate interests in maintaining the security, reliability and performance of the Services and preventing misuse.

Compliance with legal obligations.

Establishing, exercising or defending legal rights.

Explicit consent or another valid form of consent.

In countries where consent is required, consent is the legal basis for non-essential analytics and measurement technologies. In other regions where permitted by law, a proportionate legitimate interest balanced against user rights may be relied upon.

You may withdraw consent to consent-based processing at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

COOKIES AND SIMILAR TECHNOLOGIES

Passport Reports may use cookies, local storage, pixels, client identifiers or similar technologies to establish secure sessions, remember language or interface preferences, operate the artificial intelligence assistant, measure performance and understand use of the Services.

Essential session and security records are used only to operate the requested feature and prevent misuse. They may be retained for the duration of the session or for up to 30 days where required for security.

Artificial intelligence assistant session information may be retained for the duration of the session or for up to 24 hours for secure question-and-answer sessions and rate limiting.

Language, interface and passport country preferences may be stored locally on your device so that Passport Reports can remember choices you make, including the passport country you selected most recently. These preferences are used only to provide the requested site functionality and user experience. They are not used for cross-site tracking or personalised advertising and remain on your device until deleted by you, your browser, operating system or the application.

The _ga identifier and first-party identifiers beginning with ga used by Google Analytics 4 may be retained for up to 24 months.

The WordPress.com measurement service may process IP address, page, time, browser and device data to count visits and clicks. Under the provider’s standard practices, raw IP and server records may be retained for approximately 30 days. Aggregated statistics may be kept for longer.

In countries where prior consent is required, non-essential measurement technologies are not activated until a valid privacy preference has been obtained through the web layer. That preference may be withdrawn through the same web-based mechanism. A second native consent window in the Android or iOS app is not required for this purpose.

Blocking cookies may prevent some language, session or assistant features from working as expected. Refusing non-essential measurement does not prevent access to the core Passport Reports content.

ANALYTICS AND MEASUREMENT SERVICES

Passport Reports may use Google Analytics 4 to measure website traffic and controlled app web traffic.

Google Analytics may process page views, interactions, device and browser characteristics, referral information, approximate location derived from the IP address and pseudonymous client identifiers.

Passport Reports has set a maximum retention period of 14 months for Google Analytics user-level and event-level data. Reasonably anonymised or aggregated reports may be retained for longer.

Passport Reports may also use WordPress.com measurement infrastructure for visit and click statistics, service performance and reliability.

These measurement services may be used as service providers that process personal data on behalf of Passport Reports and for purposes defined by contract.

PARTIES WITH WHOM DATA MAY BE SHARED

Personal data may be shared only to the extent necessary for the stated purposes with the following parties:

Hosting, content-delivery, network, backup and security providers.

Google LLC, which provides the Google Analytics 4 measurement service.

Automattic Inc., which provides the WordPress.com measurement service.

Contracted artificial intelligence service providers that help generate a response at the user’s request.

Email and communications infrastructure providers.

App-distribution platforms such as Google Play and the Apple App Store.

Legal, technical, security and professional advisers.

Courts, regulatory bodies and authorised public authorities where there is a valid legal request.

We require these service providers to process data only in accordance with our instructions and the purposes set out in their contracts, to apply appropriate security measures and to provide protection equal to or greater than that described in this Policy.

If a merger, restructuring or transfer of the business occurs, data may be transferred only while continued adherence to this Policy and applicable legal requirements is maintained.

DATA SALES, ADVERTISING AND TRACKING

Passport Reports does not sell personal data for money.

It does not provide personal data to data brokers or create targeted advertising profiles by combining users’ behaviour across other companies’ apps or websites.

Passport Reports does not collect the Android advertising ID or Apple IDFA. It does not track users across apps and websites belonging to other companies.

If advertising, sponsorship or campaign measurement is used, raw personal data is not provided to advertisers. Aggregated or de-identified performance information is supplied wherever possible.

Before any new use involving personalised advertising or an activity treated as a “sale”, “sharing” or targeted advertising under applicable law is introduced, this Policy, app-store disclosures and any required preference mechanisms will be updated.

If a valid Global Privacy Control signal or similar legally recognised opt-out signal is received, it will be treated as a request to opt out of sale, sharing or targeted advertising to the extent required by applicable law.

INTERNATIONAL DATA TRANSFERS

Passport Reports is a global service and its contact address is in the United States. Personal data may be processed outside your country, including in the United States and in other countries where service providers maintain infrastructure.

Where there is no applicable adequacy decision for the destination country, safeguards may include the European Commission’s Standard Contractual Clauses, the United Kingdom international data transfer addendum or agreement, data-processing agreements, transfer-impact assessments, encryption, access restrictions and similar appropriate measures.

Transfers from the United Arab Emirates, Türkiye and other countries are handled with regard to relevant local data-protection rules and equivalent-protection requirements.

You may contact info@passportreports.com for information about applicable data-transfer safeguards.

DATA RETENTION

Personal data is not retained for longer than necessary for the purpose for which it was collected.

Website access, server and routine security logs are retained for up to 90 days.

Raw IP and routine server records held by the WordPress.com measurement service may be retained for approximately 30 days under the provider’s standard practices.

Google Analytics user-level and event-level data is retained for up to 14 months.

Google Analytics first-party cookie or client identifiers are retained for up to 24 months.

A question submitted to the artificial intelligence assistant and the generated response are primarily processed for the time required to provide the response. If retention is required for security or error review, they are kept for no longer than 30 days.

General communications, support correspondence and data-correction correspondence are retained for up to 24 months after the request is closed.

Privacy and data-subject request records are retained for up to 3 years after the request is resolved.

Records proving consent and preferences may be retained for the period during which the preference remains valid and for up to 5 years afterwards.

Deleted data remaining in rotating backups is overwritten or made inaccessible within no more than 90 days.

Records relating to a security incident, fraud or legal dispute may be retained only for the relevant purpose during the investigation and any applicable limitation period.

Statistics that have been anonymised or aggregated so that they cannot be linked to an individual may be retained for longer.

DELETION OF DATA

When the retention period expires, personal data is securely deleted, anonymised or made inaccessible.

When a valid deletion request is received, data that is not legally required to be retained is deleted from active systems. Copies held in backup systems disappear through the normal backup cycle and are not restored for ordinary use during that period.

Because no user account is created through the Services, there is no Passport Reports account to delete. A deletion request may nevertheless be submitted for communications, artificial intelligence assistant data, measurement records or other records.

DATA SECURITY

Passport Reports applies technical and administrative measures proportionate to the risk to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include HTTPS/TLS encryption in transit, access controls based on the principle of least privilege, secure authentication, system and dependency updates, data minimisation, backups, logging, rate limiting, abuse monitoring, provider reviews and security-incident response.

The Android app is restricted to encrypted HTTPS connections and domains permitted by Passport Reports. Cleartext traffic, mixed content, in-app JavaScript bridges, WebView debugging and unnecessary file access are disabled. Safe Browsing is used, and connections are terminated when SSL errors occur.

No method of internet transmission or storage can guarantee absolute security. If a security incident creates a risk to individuals’ rights, the competent authorities and affected individuals will be informed within the time and scope required by applicable law.

DATA-SUBJECT RIGHTS

Depending on your country and the applicable law, you may have some or all of the following rights:

To learn whether personal data about you is being processed.

To access processed personal data and request a copy.

To request correction of incomplete or inaccurate data.

To request deletion or anonymisation of data.

To request restriction of processing.

To withdraw consent you have given.

To object to processing based on legitimate interests.

To object to direct marketing.

Where applicable, to receive data in a structured, commonly used and machine-readable format or have it transferred to another controller.

Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you.

To appeal one of our decisions or request reconsideration of a request.

To lodge a complaint with the competent data-protection authority.

Not to be discriminated against or treated adversely for exercising your rights.

SUBMITTING A RIGHTS REQUEST

You may send your rights request to info@passportreports.com with the subject line “Privacy Request”.

It is sufficient to state the right you wish to exercise, the platform you used and an approximate date or session detail that will help us locate the relevant record.

Do not send a passport or identity document with your initial request.

Only reasonable and proportionate verification information may be requested to fulfil the request securely. Verification will be limited according to the nature of the requested data and the risk of unauthorised access.

Authorised representatives may apply with documentation showing their authority. Where necessary, the individual’s identity or the authority granted to the representative may be verified directly.

Valid requests are answered within the period prescribed by applicable law, generally within 30 days. Where permitted by law, this period may be extended for complex or numerous requests. The extension and its reason will be communicated within the initial period.

EUROPEAN ECONOMIC AREA, UNITED KINGDOM AND SWITZERLAND

Individuals in these regions may have rights of access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaint to the competent supervisory authority.

Where processing is based on legitimate interests, you may request an explanation of the legitimate interest relied upon and the principal elements of the relevant balancing assessment.

TÜRKİYE

Individuals covered by Türkiye’s Personal Data Protection Law No. 6698 have the right to learn whether their personal data is processed, request information and access, learn the purpose of processing, know recipients in Türkiye or abroad, request correction, deletion or destruction, request notification of those actions to recipients, object to outcomes produced solely through automated analysis and seek compensation for damage caused by unlawful processing.

UNITED ARAB EMIRATES

To the extent that United Arab Emirates personal-data protection rules apply, data subjects may have rights to information and access, data transfer, correction, deletion, restriction or cessation of processing, objection to direct marketing and objection to decisions based solely on automated processing.

CALIFORNIA AND OTHER US STATES

Under applicable state law, consumers may have the right to know the categories, sources and purposes of collected data, the categories of recipients and specific pieces of data; to delete and correct data; to opt out of data sales or sharing for targeted advertising; to limit certain uses of sensitive personal data; to data portability; to object to automated decisions or profiling; and not to be discriminated against.

During the preceding twelve months, Passport Reports may have processed technical identifiers, internet or other electronic-network activity, approximate geolocation, communication content and technical diagnostic information.

The sources of this data are the user, the user’s browser or device, Passport Reports servers and contracted service providers.

This data may be processed to provide the Services, maintain security, troubleshoot errors, communicate with users and analyse usage.

Passport Reports does not sell personal information, does not share it for cross-context behavioural advertising and has no actual knowledge that it has sold or shared for such purposes the data of anyone under 16.

OTHER COUNTRIES

You may exercise equivalent rights granted by Brazil’s LGPD, Canadian privacy legislation, Australia’s Privacy Act, Japan’s APPI, South Korea’s PIPA and other applicable data-protection laws through the same contact channel.

Where local law provides a higher level of protection than this Policy, the higher protection under local law applies.

CHILDREN’S PRIVACY

Passport Reports is a general-audience information service. It is not designed for children and is not offered under Google Play Families or the Apple Kids Category.

We do not intend knowingly to collect personal data from anyone under 16. Where local law sets a different age threshold, that threshold applies.

If you believe a child has submitted personal data without the required permission of a parent or legal representative, you may contact info@passportreports.com. We will review the circumstances and take reasonable steps to delete the data or verify the required permission.

AUTOMATED DECISION-MAKING AND PROFILING

Passport rankings and mobility scores are generated from general datasets concerning countries and travel access. They do not assess users’ personal characteristics.

Passport Reports does not decide any user’s visa, border-crossing, citizenship, immigration or other official entitlement.

Usage measurement and the artificial intelligence assistant are not used to make a solely automated decision that produces legal or similarly significant effects concerning a user.

Data is not processed to create personalised advertising profiles or determine an individual’s eligibility to travel.

ANDROID APP

The Passport Reports Android app presents web content controlled by Passport Reports within a secure WebView. Measurement, security and artificial intelligence assistant processing conducted through the website may therefore also occur while the app is used and is included in the Google Play Data Safety disclosure.

The Android app does not request permission to access precise location, camera, microphone, contacts, SMS messages, call logs, calendar, health data or advertising identifiers.

The app uses only internet and network-state access for basic network functionality.

The Android app contains no native advertising, analytics or crash-reporting SDK. Measurement takes place within controlled web content.

Third-party WebView cookies are disabled. First-party session and measurement technologies may operate as described in this Policy.

The app’s web-data clearing function removes cookies, cache, WebStorage data and browsing history. Uninstalling the app removes local data from the operating system’s app storage. A separate deletion request may be submitted for server records.

iOS AND iPadOS APPS

The Passport Reports iOS and iPadOS apps may display web content controlled by Passport Reports. The Apple App Privacy disclosure covers not only native code but also data collected through this controlled web traffic.

Passport Reports does not access Apple IDFA and does not track users across apps or websites belonging to other companies.

Access to precise location, contacts, camera, microphone, photo library, health data or similar protected Apple data would be possible only if genuinely required for a future feature explicitly initiated by the user and only after the relevant operating-system permission had first been obtained.

This Policy and the App Store privacy disclosures will be updated before any such feature is introduced.

GOOGLE PLAY AND APPLE APP STORE

Google and Apple may independently process data such as store-account information, payment methods, download history, device security and store interactions under their own terms of service and privacy policies.

Passport Reports does not access or control all data independently collected by these platforms.

The same Privacy Policy URL may be used for the website and the Android and iOS/iPadOS apps. The Google Play Data Safety and Apple App Privacy forms are completed separately and kept consistent with this Policy.

PRIVACY PREFERENCES

You may make and later change your choice through the web-based privacy-preference mechanism provided for non-essential measurement.

Cookies and locally stored preferences, including saved language, interface and passport country choices, can be deleted through your browser settings or by using the web-data clearing option in the Android app.

Clearing data from the device does not automatically delete records previously transmitted to a server. A deletion request for server records may be sent to info@passportreports.com.

If direct-marketing messages are sent, each message will provide an easy opt-out method. Service and security notices are not direct marketing.

THIRD-PARTY LINKS

The Services may contain links to government bodies, official travel resources, social networks or independent websites.

When you open an external link, the relevant third party is responsible for its own privacy policy and data practices.

The presence of a link on Passport Reports does not mean that the third party endorses Passport Reports or that Passport Reports acts on behalf of that organisation.

SECURITY INCIDENTS

If a personal-data breach occurs, we assess the nature of the incident, the types of data affected, the likely consequences and the measures taken.

Where the incident creates a risk to individuals’ rights and freedoms that requires notification, the relevant data-protection authority and affected individuals will be informed within the time and scope required by applicable law.

CHANGES TO THIS POLICY

This Policy may be updated if the Services, providers used, types of data processed or applicable law change.

The effective date and last-updated date of the current version are shown at the beginning of the page.

Where a material change is made, a prominent notice within the Services or another appropriate method may be used depending on the nature of the change.

Where consent is required for a new purpose, the necessary consent will be obtained before personal data is processed for that new purpose.

Previous versions of the Policy may be archived for accountability purposes.

RIGHT TO COMPLAIN

Contacting Passport Reports first may help resolve an issue more quickly. You nevertheless retain the right to lodge a complaint with the competent data-protection or consumer-privacy authority where you are located.

The relevant authority may be a national supervisory authority in the European Economic Area, the United Kingdom Information Commissioner’s Office, Türkiye’s Personal Data Protection Authority, the competent data authority in the United Arab Emirates, the California Privacy Protection Agency or another competent body in your country.

CONTACT

For questions, objections, access, correction or deletion requests concerning this Privacy Policy or your personal data:

Passport Reports

1 Seneca St

Buffalo, NY 14203

United States

Email: info@passportreports.com

Telephone: +1 (716) 414-2228

Using “Privacy Request” in the subject line will help route your request to the correct channel more quickly.