Privacy policy
An immigration file is among the most sensitive collections of information a person has. Here is exactly what happens to yours.
Version 1.0 · අවසන් වරට යාවත්කාලීන කළේ 10 Sep 2026. වැදගත් වෙනසක් බලපැවැත්වීමට පෙර අපි ලියාපදිංචි පරිශීලකයන්ට දන්වමු.
Application servers and the database, including every uploaded document, are hosted in Sydney, Australia. Administrative access is exercised from the United States and the Philippines. We are a United States company, so this policy explains the cross-border position honestly rather than burying it.
1. Which law applies to us
We are MultiTasker LLC, a limited liability company registered in the State of Wyoming, United States of America. The Privacy Act 1988 (Cth) applies to a foreign organisation with an "Australian link" - one that carries on business in Australia and collects or holds personal information in Australia. We do both, so we treat ourselves as bound by the Australian Privacy Principles and we comply with them regardless of whether a small business exemption might otherwise be available to us. We also comply with the Notifiable Data Breaches scheme.
Since June 2025 an individual can also sue directly for a serious invasion of privacy. We mention it because it is a right you have, not because we are obliged to advertise it.
2. What we collect
- Account: name, email, phone if you give one, password (stored only as a scrypt hash), language preference, and two-factor settings.
- Case: the visa you are seeking, nationality, current visa status, family composition, timeframe, budget, and whatever you write in your own words.
- Documents: anything you upload to an engagement. This is usually sensitive information - identity documents, health and police checks, financial records, relationship evidence.
- Activity: messages, quotes, payments, and an audit log of actions taken on your account, including IP address and browser string at sign-in.
We do not use advertising trackers, we do not embed third-party analytics, and we set no cookie that is not necessary to make the site work - a session cookie, a CSRF cookie, and a short-lived message cookie. There is no cookie banner because there is nothing to consent to.
3. Who can see your case
Before you engage anyone: providers see the facts of your case without your identity. No name, no email, no phone. Contact details in messages are masked automatically in both directions until an engagement starts.
After you engage someone: your identity and contact details are released to that one provider. Not to the others, who see only that the case closed.
Documents are visible to you, to the provider on that engagement, and to VisaBid staff only where it is necessary to resolve a dispute or comply with the law. They are never served from a guessable URL; every download is authorised individually and logged.
4. Cross-border disclosure
Your information is stored in Australia. It is accessible to our personnel outside Australia, in the United States and the Philippines, for support, security and administration. Under Australian Privacy Principle 8 we remain accountable for how it is handled once it leaves Australia, and we accept that accountability rather than contracting out of it.
We use Stripe, Inc. to process payments. Stripe receives your name, email and payment details directly; we never see or store your card number.
5. How long we keep it
- Engagement records: seven years. This matches the professional obligation on your provider under section 56 of the Code, and means the record still exists if you need it.
- Cases that never became an engagement: deleted on request, and otherwise after two years.
- Money and audit records: seven years.
- Documents: deleted with the engagement record, or earlier on request, subject to any legal hold.
Note that your provider has an independent obligation to keep their own file for seven years. We cannot delete their copy and would not be entitled to.
6. Your rights
- Access and correct your information from your account at any time.
- Export a complete engagement file - every document, every event, the whole money trail - from the engagement page. No request, no waiting.
- Ask us to delete your account and cases: privacy@visabid.io.
- Complain to us, and then to the Office of the Australian Information Commissioner if you are not satisfied.
7. Security
- Everything is served over TLS.
- Passwords are stored as scrypt hashes and are never recoverable, by us or by anyone.
- Two-factor authentication is required for provider and administrator accounts and available to everyone.
- Uploads are checked against their actual file signature, stored outside the web root under random names, and served only through an authorisation check.
- A strict content security policy, no third-party scripts, and no external asset hosts.
No system is perfectly secure. If we suffer a data breach likely to cause you serious harm, we will assess it within 30 days and notify you and the OAIC as the Notifiable Data Breaches scheme requires. If you find a vulnerability, please tell us at privacy@visabid.io - we will not pursue anyone who reports one in good faith and does not exfiltrate other people's data.
8. What we will never do
We do not sell your data. We do not sell leads. We do not pass your contact details to providers who have not been chosen by you. A marketplace that sells the contact details of anxious visa applicants is a different and much worse business, and we are not in it.
ඒවා ප්රවේශමෙන් සහ වත්මන් නීතිය සැලකිල්ලට ගනිමින් සකස් කර ඇත, නමුත් ඒවා Australian legal practitioner කෙනෙකු විසින් settled කර නැත. ඔබ ඒවා ව්යාපාරයක් පවත්වාගෙන යාම සඳහා භාවිතා කරන්නේ නම්, ඒවා සමාලෝචනය කරවා ගන්න. ඔබ ඔබේ අයිතිවාසිකම් තේරුම් ගැනීමට ඒවා මත රඳා සිටින පරිශීලකයෙකු නම්, Australian Consumer Law යටතේ ඔබේ අයිතිවාසිකම් ඕනෑම ලේඛනයක සඳහන් දේ කුමක් වුවත් පවතින බව සලකන්න.