Privacy Policy

HeadFirstServices LLC  ·  Last updated: June 2026

HeadFirstServices LLC ("we", "us", or "our") operates the following mobile applications (collectively, "the Apps"):

This Privacy Policy applies to all of the above. Where practices differ between apps, that is noted explicitly.

1. Information We Collect

Account information All apps

When you create an account you provide your email address and a password (stored as a salted hash — we never see it in plain text). A unique user ID is generated and associated with all your data.

Profile information All apps

You may optionally provide a home currency and passport / nationality. This is used to personalise the app experience and is never sold or shared with advertisers.

Trip and travel data VisaStay

Trip records you create include: destination country, city, start and end dates, passport used for entry, and optional free-text notes. This data is stored securely in your account and is not accessible to other users.

Packing data PackLite

Packing lists you create include: destination(s), travel dates, trip purpose, transport type, bag type, and individual packing items with their status (packed / used / not used / wish I'd brought). Post-trip feedback you submit is stored to power personalised future recommendations — within your account only.

Notification preferences VisaStay

If you enable push or email notifications, we store your configured alert rules (e.g. days before visa expiry) and your device push token. You can delete or disable these at any time from within the app.

Device and usage data

We do not collect analytics, crash reports, advertising identifiers, or behavioural tracking data. We do not use any third-party analytics SDK.

Payment data Pro subscriptions

Subscription purchases are processed by RevenueCat and the underlying app store (Apple App Store or Google Play). We receive only a subscription status flag (active / expired). Your payment card details are never transmitted to or stored by us.

2. How We Use Your Information

We do not use your data for advertising, profiling, or sale to third parties.

3. Third-Party Services and Data Processors

We use the following sub-processors. Each is bound by a Data Processing Agreement (DPA) where required.

Processor Purpose Data shared Location
Supabase Inc. Database, authentication, file storage All user account and app data US East (AWS)
Resend Inc. Transactional email delivery Your email address and message content United States
RevenueCat Inc. Subscription management App store purchase receipts, subscription status United States
Open-Meteo Weather forecasts PackLite Destination coordinates (no personal identifiers) European Union

No other third parties receive your personal data. The Apps contain no advertising SDK, social login, or third-party tracking library.

4. Data Retention

Your data is retained for as long as your account exists. If you delete your account, all personal data associated with that account is permanently deleted from our systems within 7 days, except where retention is required by applicable law.

Anonymised, non-identifiable aggregates may be retained indefinitely.

5. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@headfirstservices.com. We will respond within 30 days.

If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.

6. Account and Data Deletion

You can delete your account directly within each app (Profile → Delete Account). This opens an email to privacy@headfirstservices.com; your account and all associated data will be permanently deleted within 7 days.

Deleting your account in one app does not affect accounts in our other apps — each app maintains a separate data scope.

You may also submit a deletion request here: delete-account page.

7. Data Breach Notification

In the event of a personal data breach likely to result in risk to your rights and freedoms, we will:

8. International Data Transfers

Your data is stored on servers in the United States (Supabase / AWS US East). If you are in the European Economic Area, this constitutes a transfer of personal data outside the EEA. Such transfers are covered by Standard Contractual Clauses (SCCs) incorporated into our agreement with Supabase.

9. Children's Privacy

The Apps are not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@headfirstservices.com and we will delete it promptly.

10. Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, row-level security on all database tables so users can only access their own data, and bcrypt password hashing. No method of internet transmission is 100% secure, but we take reasonable precautions to protect your information.

11. Changes to This Policy

When we update this policy, we will revise the "Last updated" date above. For material changes, we will notify you by email or in-app notice at least 14 days before the change takes effect. Continued use of the Apps after that date constitutes acceptance.

12. Contact

HeadFirstServices LLC — Washington State, USA
Email: privacy@headfirstservices.com

For GDPR enquiries or to exercise your data rights, use the same address. We aim to respond within 30 days.