Privacy Policy
Last updated: 1 September 2026
Privacy at a glance
VisaCapAlert watches a government web page and emails you when the country you chose changes status. To do that we need your email address and your chosen country — and very little else. We do not sell your data, we do not build a profile of you, and we never send your email address to an analytics or advertising company.
Who is responsible for your data
The data controller is WONDRATECH PTY LTD (trading as Status Alert Technologies), ABN 51 633 863 966.
Level 4, 29 Kiora RoadMiranda NSW 2228
Australia
privacy@visacapalert.com
Our representative in the EU
We are established in Australia, so we have appointed a representative in the European Union under Article 27 GDPR. You may contact them about anything to do with your personal data, in place of contacting us directly.
Asafe WondracekEU Representative under Article 27 GDPR
PO Box 0005
2410 Hainburg an der Donau
Austria
eu-representative@visacapalert.com
What we collect, why, and for how long
| Information | Why we hold it | Our legal basis | How long |
|---|---|---|---|
| Your email address and chosen country The address you sign up with and the country whose cap you asked us to watch. | To send you the alert you paid for, and to verify the address belongs to you. | Performance of our contract with you | Until 12 months after your alert ends, or immediately on request. |
| Verification state Whether your address has been verified, when a code was sent, how many attempts were made, and a one-way hash of the code. The code itself is never stored. | To prove the address is yours and to stop the signup form being abused. | Performance of our contract; our legitimate interest in preventing abuse | Codes expire after 30 minutes. The rest is deleted with your record. |
| Payment references Stripe's payment, subscription and customer identifiers, the amount and currency you paid, and the billing country Stripe collected. We never see or store your card number. | To take payment, manage your subscription, handle refunds, and meet our tax obligations. | Performance of our contract; compliance with a legal obligation | Your record is deleted on request; a transaction record with no personal identifiers is kept for accounting and VAT reporting. |
| Phone number (only if you choose WhatsApp alerts) The number you verified, and whether the opt-in is active. | To send cap alerts over WhatsApp. Entirely optional — the email alert works without it. | Your consent, given by opting in | Until you remove it, or your record is deleted. |
| Analytics A random identifier stored in your browser, plus which pages you viewed, your screen size, browser and referring page. Never your email address or any other detail that identifies you. | To see which pages people reach and where the signup process loses them. | Your consent, where we ask for it | 14 months. |
| Advertising identifiers Cookies set by Meta (_fbp, _fbc), your IP address and browser user-agent, and the campaign source in the link you arrived through. | To measure whether our ads on Google and Meta actually lead to signups. This is the only category we share with third parties. | Your consent | Cleared as soon as your alert ends, or immediately if you withdraw consent or ask us to remove them. |
| Referral information Your own referral code, any code you redeemed, and a count of friends who signed up through yours. | To apply your discount and to work out any reward you have earned. | Performance of our contract | Deleted with your record. |
| Delivery and suppression records Short-lived records of an alert we failed to deliver, and a marker if a message to your address hard-bounced or was reported as spam. | To fix delivery problems, and to stop emailing an address that cannot receive mail. | Our legitimate interest in a working, well-behaved email service | Delivery failures: 7 days. A do-not-email marker is kept indefinitely — if you ask us to erase your data we replace it with a one-way hash of your address, so we can keep refusing to email you without holding the address. See “If we can’t email you”. |
| Privacy and withdrawal requests A record of a request you make to us, what we did about it, and when. | To show that we handled your request, and within the time the law allows. | Compliance with a legal obligation | 3 years for privacy requests; 6 years for withdrawal requests. |
Who we share it with
We use a small number of service providers to run VisaCapAlert. We do not sell your personal data, and we do not share it with anyone other than the providers below.
| Provider | What for | Where | Needs your consent? |
|---|---|---|---|
| Amazon Web Services | Hosting, storage and email delivery | Australia (Sydney) | No |
| Stripe | Payment processing and VAT calculation | United States and Ireland | No |
| Meta (WhatsApp Business Platform) | Delivering WhatsApp alerts, if you opted in | United States | No |
| Meta (Pixel and Conversions API) | Measuring our advertising | United States | Yes |
| Google (Ads) | Measuring our advertising | United States | Yes |
Where your data is stored
VisaCapAlert runs on Amazon Web Services in Sydney, Australia. If you are in the European Economic Area, this means your personal data is transferred outside the EEA. Some of our providers are also in the United States. We rely on the appropriate safeguards for those transfers, and you can ask us for details.
Your rights
If you are in the EEA or the UK, you have the right to:
- Access — ask for a copy of the personal data we hold about you.
- Portability — receive that copy in a structured, machine-readable format. We provide JSON or CSV.
- Rectification — have inaccurate data corrected. Note that your email address and chosen country identify your alert, so changing either means registering again rather than editing in place.
- Erasure — have your data deleted. We will delete your alert record and everything linked to it. We keep a transaction record for accounting and VAT reporting, but it holds no email address, name, phone number, IP address or device identifier, and it is keyed by a random reference, so it cannot be traced back to you from our systems. If your address is on our do-not-email list we keep a one-way hash of it, so that deleting your record does not start us emailing you again — see If we can’t email you below.
- Restriction and objection — have us stop processing that is not strictly necessary.
- Withdraw consent — at any time, for anything you consented to. Use for cookies, or email us for anything else. Withdrawing consent does not affect processing we already did while it was valid.
To exercise any of these, email privacy@visacapalert.com or contact our EU representative. We will respond within one month.
If we can’t email you
If an email to your address permanently fails, or is reported as spam, we record a marker so that we do not email that address again. We keep that marker for as long as the service runs: forgetting it would mean emailing an address that cannot receive mail, which is bad for you and for our ability to deliver mail to anyone else.
If you ask us to erase your data, we do not simply delete the marker — that would let a later signup start emailing the address all over again. Instead we replace it with a one-way cryptographic hash of the address, computed with a secret key. The hash cannot be turned back into an email address. We can only check it: when an address is entered into our signup form we hash that address and compare the two. Nothing else in our systems can use it, and we do not share it with anyone.
Complaints
If you think we have handled your personal data incorrectly, please contact us first — we would appreciate the opportunity to address your concerns.
You also have the right to lodge a complaint with a data protection supervisory authority, including the authority in the EU country where you live or work. You may also contact the Österreichische Datenschutzbehörde (Austrian Data Protection Authority), where our EU representative is based.
Cookies and similar technologies
We use cookies and browser storage that are necessary to run the service, and — only with your permission — analytics and advertising cookies. Full detail is in our Cookie Policy, and you can change your choice at any time using .
Automated decision-making
We do not make any decision about you by automated means that produces legal effects or similarly significantly affects you. Your alert is triggered by a change on a government web page, not by any assessment of you.
Children
VisaCapAlert is intended for adults applying for working holiday visas. We do not knowingly collect data from children.
Changes to this policy
If we change how we handle your data we will update this page and the date at the top. If the change is material and affects something you consented to, we will ask you again.
Contact
Privacy questions: privacy@visacapalert.com
Anything else: support@visacapalert.com
EU representative: eu-representative@visacapalert.com
