Security
Your details, kept safe.
We only ask for what your application needs, and we look after it properly. Here’s how.
-
Encrypted, start to finish. Your passport details, documents and answers are encrypted on the way to us and while we hold them. Even a copy of our database wouldn’t give them away.
-
No card details on file. You pay on our payment provider’s secure form. Your card number never reaches our systems, so there’s nothing here to steal.
-
No password to steal. You sign in with a one-time link we email you. It works once and expires quickly, so there’s no password to guess, reuse or leak.
-
Only the people who need it. Our team only sees what their role needs, and access is removed when that changes. Every time someone opens your documents, it’s logged.
-
Checked before it’s stored. Every upload is checked and cleaned before we keep it, including stripping the hidden location data phones add to photos. Only you and the people handling your application can open it.
-
Kept only as long as it’s needed. We delete what we no longer need on a fixed schedule. You can ask us to delete your data at any time, and we’ll tell you exactly what we have to keep.
We never sell your data, and we don’t use advertising trackers. Our privacy policy explains what we hold, why, and for how long. Questions about your data? Email [email protected].
Is that email really from us?
Scammers copy visa services because travellers expect to hear from one. Here’s how to tell it’s really us.
- Our emails come from an address ending in @help.crownvisa.co.uk.
- We’ll never ask for your card details by email, phone or text.
- We’ll never ask you to email us your passport. Uploads happen inside your application.
- Not sure? Don’t click. Type app.crownvisa.co.uk into your browser yourself, or contact our support team.
Found a security issue?
If you’ve found a weakness in this site, we want to hear about it, and we won’t come after you for telling us.
- Security contact
- [email protected]
- We aim to reply
- Within 6 business days
What helps
- The page or address, what you did, and what happened
- Enough detail for us to reproduce it (a short recording is fine)
- What you think the impact is
- How to reach you if we have a question
What we ask
- Only test with your own data. Don’t access, change or download anyone else’s. If a flaw would let you, stop there and tell us.
- Don’t do anything that disrupts travellers: no denial-of-service, no high-volume automated scanning, no social engineering of our team or partners, and no physical testing.
- Give us a fair chance to fix it before you publish anything, and tell us if you plan to.
We don’t run a paid bug bounty, but we’re glad to credit you publicly once a fix is out, if you’d like.
Questions about your own application?
Our support team can see your file and give you a proper answer.