Privacy Policy

Last updated: 1 September 2026

Privacy at a glance

VisaCapAlert watches a government web page and emails you when the country you chose changes status. To do that we need your email address and your chosen country — and very little else. We do not sell your data, we do not build a profile of you, and we never send your email address to an analytics or advertising company.

Who is responsible for your data

The data controller is WONDRATECH PTY LTD (trading as Status Alert Technologies), ABN 51 633 863 966.

Level 4, 29 Kiora Road
Miranda NSW 2228
Australia
privacy@visacapalert.com

Our representative in the EU

We are established in Australia, so we have appointed a representative in the European Union under Article 27 GDPR. You may contact them about anything to do with your personal data, in place of contacting us directly.

Asafe Wondracek
EU Representative under Article 27 GDPR
PO Box 0005
2410 Hainburg an der Donau
Austria
eu-representative@visacapalert.com

What we collect, why, and for how long

InformationWhy we hold itOur legal basisHow long
Your email address and chosen country
The address you sign up with and the country whose cap you asked us to watch.
To send you the alert you paid for, and to verify the address belongs to you.Performance of our contract with youUntil 12 months after your alert ends, or immediately on request.
Verification state
Whether your address has been verified, when a code was sent, how many attempts were made, and a one-way hash of the code. The code itself is never stored.
To prove the address is yours and to stop the signup form being abused.Performance of our contract; our legitimate interest in preventing abuseCodes expire after 30 minutes. The rest is deleted with your record.
Payment references
Stripe's payment, subscription and customer identifiers, the amount and currency you paid, and the billing country Stripe collected. We never see or store your card number.
To take payment, manage your subscription, handle refunds, and meet our tax obligations.Performance of our contract; compliance with a legal obligationYour record is deleted on request; a transaction record with no personal identifiers is kept for accounting and VAT reporting.
Phone number (only if you choose WhatsApp alerts)
The number you verified, and whether the opt-in is active.
To send cap alerts over WhatsApp. Entirely optional — the email alert works without it.Your consent, given by opting inUntil you remove it, or your record is deleted.
Analytics
A random identifier stored in your browser, plus which pages you viewed, your screen size, browser and referring page. Never your email address or any other detail that identifies you.
To see which pages people reach and where the signup process loses them.Your consent, where we ask for it14 months.
Advertising identifiers
Cookies set by Meta (_fbp, _fbc), your IP address and browser user-agent, and the campaign source in the link you arrived through.
To measure whether our ads on Google and Meta actually lead to signups. This is the only category we share with third parties.Your consentCleared as soon as your alert ends, or immediately if you withdraw consent or ask us to remove them.
Referral information
Your own referral code, any code you redeemed, and a count of friends who signed up through yours.
To apply your discount and to work out any reward you have earned.Performance of our contractDeleted with your record.
Delivery and suppression records
Short-lived records of an alert we failed to deliver, and a marker if a message to your address hard-bounced or was reported as spam.
To fix delivery problems, and to stop emailing an address that cannot receive mail.Our legitimate interest in a working, well-behaved email serviceDelivery failures: 7 days. A do-not-email marker is kept indefinitely — if you ask us to erase your data we replace it with a one-way hash of your address, so we can keep refusing to email you without holding the address. See “If we can’t email you”.
Privacy and withdrawal requests
A record of a request you make to us, what we did about it, and when.
To show that we handled your request, and within the time the law allows.Compliance with a legal obligation3 years for privacy requests; 6 years for withdrawal requests.

Who we share it with

We use a small number of service providers to run VisaCapAlert. We do not sell your personal data, and we do not share it with anyone other than the providers below.

ProviderWhat forWhereNeeds your consent?
Amazon Web ServicesHosting, storage and email deliveryAustralia (Sydney)No
StripePayment processing and VAT calculationUnited States and IrelandNo
Meta (WhatsApp Business Platform)Delivering WhatsApp alerts, if you opted inUnited StatesNo
Meta (Pixel and Conversions API)Measuring our advertisingUnited StatesYes
Google (Ads)Measuring our advertisingUnited StatesYes

Where your data is stored

VisaCapAlert runs on Amazon Web Services in Sydney, Australia. If you are in the European Economic Area, this means your personal data is transferred outside the EEA. Some of our providers are also in the United States. We rely on the appropriate safeguards for those transfers, and you can ask us for details.

Your rights

If you are in the EEA or the UK, you have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Portability — receive that copy in a structured, machine-readable format. We provide JSON or CSV.
  • Rectification — have inaccurate data corrected. Note that your email address and chosen country identify your alert, so changing either means registering again rather than editing in place.
  • Erasure — have your data deleted. We will delete your alert record and everything linked to it. We keep a transaction record for accounting and VAT reporting, but it holds no email address, name, phone number, IP address or device identifier, and it is keyed by a random reference, so it cannot be traced back to you from our systems. If your address is on our do-not-email list we keep a one-way hash of it, so that deleting your record does not start us emailing you again — see If we can’t email you below.
  • Restriction and objection — have us stop processing that is not strictly necessary.
  • Withdraw consent — at any time, for anything you consented to. Use for cookies, or email us for anything else. Withdrawing consent does not affect processing we already did while it was valid.

To exercise any of these, email privacy@visacapalert.com or contact our EU representative. We will respond within one month.

If we can’t email you

If an email to your address permanently fails, or is reported as spam, we record a marker so that we do not email that address again. We keep that marker for as long as the service runs: forgetting it would mean emailing an address that cannot receive mail, which is bad for you and for our ability to deliver mail to anyone else.

If you ask us to erase your data, we do not simply delete the marker — that would let a later signup start emailing the address all over again. Instead we replace it with a one-way cryptographic hash of the address, computed with a secret key. The hash cannot be turned back into an email address. We can only check it: when an address is entered into our signup form we hash that address and compare the two. Nothing else in our systems can use it, and we do not share it with anyone.

Complaints

If you think we have handled your personal data incorrectly, please contact us first — we would appreciate the opportunity to address your concerns.

You also have the right to lodge a complaint with a data protection supervisory authority, including the authority in the EU country where you live or work. You may also contact the Österreichische Datenschutzbehörde (Austrian Data Protection Authority), where our EU representative is based.

Cookies and similar technologies

We use cookies and browser storage that are necessary to run the service, and — only with your permission — analytics and advertising cookies. Full detail is in our Cookie Policy, and you can change your choice at any time using .

Automated decision-making

We do not make any decision about you by automated means that produces legal effects or similarly significantly affects you. Your alert is triggered by a change on a government web page, not by any assessment of you.

Children

VisaCapAlert is intended for adults applying for working holiday visas. We do not knowingly collect data from children.

Changes to this policy

If we change how we handle your data we will update this page and the date at the top. If the change is material and affects something you consented to, we will ask you again.

Contact

Privacy questions: privacy@visacapalert.com
Anything else: support@visacapalert.com
EU representative: eu-representative@visacapalert.com