1.Introduction
This Privacy Policy explains how Orizn (“Orizn”, “we”, “us”) handles information when you install or use the Orizn visa checker Chrome extension (the “Extension”) distributed at extension.orizn.app and via the Chrome Web Store.
Orizn is built by a small independent team. We do not sell data and we have no commercial interest in collecting anything we don’t strictly need. Where this policy can be replaced by an objective statement of fact, we prefer that — for example, “the passport country is stored inchrome.storage.sync” is more useful than a generic clause about “local device storage”.
1.1 Who this applies to
This policy applies to all users of the Extension worldwide. If you are located in the European Economic Area, the United Kingdom, Switzerland or California, additional regional rights are described in Section 6.
1.2 Data controller
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, the data controller is Orizn, contactable at [email protected].
2.Data we collect
The Extension is designed to keep almost everything on your device. The data we touch falls into three buckets:
2.1 Stored locally in your browser
- Passport country code. Your selected passport country (e.g.
FR,VN) is stored inchrome.storage.sync, which means it travels across the Chrome instances signed into the same Google account. It never reaches our servers as an account attribute. - Recent destination lookups. Up to one hour of destination cache is held locally to avoid redundant API calls.
- UI preferences. Display language, theme and last-seen changelog version are stored locally.
- Optional API key. If you opt into the paid tier, the API key issued to you is stored in
chrome.storage.syncand is only ever sent tovisa.orizn.appfor authentication.
2.2 Sent to /api/visa on each lookup
When you trigger a visa check, the Extension sends a request to https://visa.orizn.app/api/visa containing only:
- your passport country code (e.g.
FR); - your destination country code (e.g.
TH); - your optional API key, if you have one;
- standard HTTP headers automatically attached by Chrome (User-Agent, Accept-Language).
No name, email, device identifier, browsing history, referrer URL, IP-derived geolocation, page contents or DOM scrape is included in these requests. Server logs retain the truncated IP and request line for up to seven days for abuse prevention, after which they are deleted.
2.3 Account data (paid tiers only)
If you create an Orizn account to subscribe to a paid tier, we additionally process: your email address, hashed password (or OAuth subject ID if you sign in with Google or Apple), subscription status, and billing metadata returned by Stripe (last four digits of the card, country of card issuer, invoice history). We do not store full card numbers — Stripe does, as a Level 1 PCI-DSS certified processor.
4.How we use data
Each category of data is processed for one of a small number of purposes:
4.1 Providing the service
Passport code + destination code are processed to return the correct visa requirement. The legal basis under GDPR Art. 6(1)(b) is the performance of the contract — without this data the service cannot function.
4.2 Improving accuracy
Aggregated, non-identifying request statistics (e.g. “how many people asked for FR→THlast week”) help us prioritize which country pairs to re-verify. We do not aggregate by user.
4.3 Billing and account management
Email and Stripe-returned metadata are processed to send invoices, prevent fraud, and let you manage your subscription. Legal basis: performance of contract and compliance with French tax law.
4.4 What we do NOT do
- We do not run behavioral profiling.
- We do not use your data to train AI models.
- We do not sell or rent data — ever.
- We do not enrich your profile with third-party data brokers.
6.Your rights (GDPR + CCPA)
6.1 If you are in the EU / UK / Switzerland
Under GDPR you have the right to: access your personal data (Art. 15), rectify it (Art. 16), erase it (Art. 17), restrict its processing (Art. 18), data portability (Art. 20), object to processing (Art. 21), and lodge a complaint with a supervisory authority (Art. 77). The lead supervisory authority for Orizn is the CNIL (France): cnil.fr.
6.2 If you are in California
Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, you may request to know what personal information we hold, to delete it, to correct it, and to opt out of any “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under the CCPA.
6.3 How to exercise a right
Email [email protected] from the address associated with your account. We will respond within 30 days. There is no fee for the first request in any 12-month period.
7.Data retention
- Local storage. Persists until you uninstall the Extension or clear Chrome storage. We have no control or visibility over this.
- Web server access logs. Retained for up to 14 days, then automatically rotated out.
- API request logs. When you call the Visa API with a key, we record the request (endpoint, passport and destination codes, status, response time) together with the originating IP address. We keep these for up to 12 months on the legal basis of legitimate interest, for one purpose: detecting and investigating abuse of the API. This is not theoretical — on 19 July 2026 these logs are what let us identify and stop a coordinated scraping operation. They are never used for advertising, profiling or resale.
- Account record. Retained for as long as your account exists. On account deletion, your record is fully erased from our primary database within 30 days. Backups are encrypted, rolling, and purged within 35 days.
- Invoices. Retained for 10 years to comply with French accounting law (article L123-22 of the Code de commerce).
8.Children
The Extension is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided personal information to us, contact [email protected] and we will delete it without delay.
9.International transfers
Our primary infrastructure is in Germany (EU). Some sub-processors (notably Stripe and Cloudflare) are headquartered in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (2021/914) and, where applicable, the EU-US Data Privacy Framework certifications of those processors.
10.Security
We use defense-in-depth practices appropriate to the small scale and low-sensitivity nature of the data we handle:
- TLS 1.3 for all network communication.
- Argon2id password hashing.
- Stripe-hosted card capture (we never see card numbers).
- Disk encryption at rest (LUKS) and encrypted backups.
- Principle of least privilege for production access.
- Annual third-party review of authentication flows.
No security program is perfect. If you discover a vulnerability, please report it to [email protected]. We do not pursue legal action against good-faith researchers who comply with our disclosure guidelines.
12.Contact and Data Protection Officer
Questions, complaints, or requests under any privacy law:
- Privacy team: [email protected]
- Data Protection Officer (DPO): [email protected]
- General support: [email protected]
- Postal address: available on request to data subjects exercising rights under GDPR.
See also our companion document, the Terms of Service, which governs how you use the Extension.
This document was last reviewed on May 30, 2026. Material changes will be announced via the in-extension changelog and, for account holders, by email at least 14 days before they take effect.