Effective 13 September 2026
Privacy, in plain language.
The public access map works without an account. Paar collects personal information only when you save a trip, store a document, ask for visa help, or contact us.
What stays on your device
Passports, visas, permits, and expiry dates you add to the access explorer are stored in your browser. Paar does not receive them through the discovery product. Clearing site data removes that local profile.
What your account stores
When you use an account, Paar may store:
- your email address and basic Google profile if you use Google sign-in;
- saved itineraries, flights, residency, employment, funding, and eligibility answers;
- places you choose to remember, visit dates, and your notes about those trips;
- documents you choose to keep in your private document store;
- checklist progress, reviewer decisions, application events, and support messages;
- security and reliability logs needed to operate the service.
Documents are private, type-checked at upload, and served through short-lived download links. Paar does not malware-scan uploads or attach them to email.
Optional AI travel ideas
Paar generates ordinary recommendations on-device. If you choose “Use my notes,” Paar sends your saved travel notes, the relevant access descriptions, and a limited list of eligible destinations to Google's Gemini API to rerank those options. Paar does not send documents, passport numbers, email addresses, or your account ID in that recommendation request, and does not enable optional request-log sharing. Do not put sensitive personal information in travel notes.
Reading booking PDFs
When you attach a flight or hotel PDF in the trip planner, Paar first stores it in your private document account and runs the configured security scan. If it passes, Paar sends that PDF to Google's Gemini API to extract booking details into editable itinerary fields. Check every extracted value before saving; the PDF remains the source document and extraction can be incomplete or wrong.
Reviewer copilot
When a reviewer asks the internal copilot to draft a case memo, Paar sends Google's Gemini API the application facts, checklist, deadlines, and structured fields already extracted from relevant account documents. It does not send document files or storage links in this step. The draft cannot change a requirement, contact you, or submit an application; a reviewer checks the cited evidence and makes every decision.
Why we use it
- to work out the visa requirements for your itinerary;
- to prepare, review, and coordinate an application you request;
- to protect accounts, investigate errors, and meet legal obligations;
- to measure service quality using operational, not advertising, data.
Paar does not sell personal information and does not use visa-application details for targeted advertising.
Product measurement
Paar records a small set of first-party events—page views, opening a visa route, starting a trip, or beginning an application—using two random identifiers kept in your own browser: one that persists so visitors can be counted, and one that resets after thirty minutes idle so visits can be. Neither is a fingerprint; clearing your site data resets both. These events contain only the passport country, destination, product surface, page path, and event time. They do not contain names, contact details, travel credentials, form answers, or documents. While you are signed in, events are linked to your account so we can tell whether the product helped; that link is made on our server and a browser cannot claim someone else’s account. Paar respects the browser’s Do Not Track setting, records nothing at all when it is set, and uses no advertising trackers.
If you report incorrect visa information, Paar stores the route, issue category, your written explanation, submission time, and a one-time random submission identifier. Do not include contact details, passport numbers, or personal documents in a correction report.
Google sign-in
Google sign-in provides your identity, email address, and basic profile. Paar requests only the openid, email, and profile scopes. It does not request access to Gmail, Google Drive, contacts, calendars, or passwords.
Processors and access
Supabase provides authentication, database, and private storage services; the current project is hosted in Frankfurt. Google provides optional sign-in. Google processes travel notes when you request AI travel ideas, booking PDFs when you request itinerary extraction, and structured application facts when an authorised reviewer requests a copilot case memo under the Gemini API terms. Hosting and email providers may process limited technical data. Reviewers receive only the access required for assigned application work. Paar does not send applicant documents by ordinary email.
Retention and control
Documents in your document store do not expire automatically; they remain available for future trips until you remove them or close your account. Application and payment records may be retained while needed to deliver the service, handle disputes, secure the system, or meet applicable obligations.
Your self-service application checklist, appointment details, and filing record are included in your account export and deleted when you delete their trip or your account is erased.
You can download everything your account holds, and close it, from your account page. Closing schedules deletion in 30 days: nothing is removed until then and you can cancel it by signing in, which is there so a mistake or a stolen session is recoverable. On that day your details, trips, travel history, stored documents and their files are erased, and the files are deleted from storage rather than hidden.
Where an account holds visa application or payment records, those are kept after the rest is erased, because we are obliged to be able to answer for a transaction. Your account will say that it kept them. To ask about anything else, email privacy@getpaar.com.
Changes and questions
Material changes will be dated on this page. Questions or security concerns can be sent to privacy@getpaar.com.