Legal

The fine print, in plain English

Mileskeeper handles sensitive travel information. This page explains what we collect, how we use it, and what security controls are currently in place.

Privacy

Last updated: September 2026

We collect information needed to support travel and visa workflows, including contact details, passport and nationality details, destination plans, payment state, uploaded documents, and trip files you choose to store.

Documents are stored in private application storage. When cloud storage is configured, provider-side encryption can be enabled through the storage provider. Access is limited to the customer, assigned staff, and administrators with a business need.

We share application information only with service providers, payment processors, embassies, consulates, visa centres, or travel partners needed to process the service you requested.

You can request access, correction, export, or deletion by emailing privacy@mileskeeper.com. Some records may be retained where required for fraud prevention, tax, audit, dispute, or legal obligations.

Terms of Service

Last updated: September 2026

Mileskeeper is an assistance and organization service. We do not issue visas. Final decisions, appointment availability, processing times, and entry permission remain with the destination government or border authority.

You agree to provide accurate information and authentic documents. False, incomplete, or late information can cause delay, refusal, cancellation, or loss of fees.

Pricing, included services, and processing assumptions are shown before checkout. Government and third-party fees may be separate from Mileskeeper service fees.

Refund Policy

Last updated: September 2026

Before submission. You may request cancellation before Mileskeeper starts submission or specialist work. Eligible service-fee refunds are reviewed against the work already performed.

After submission. Government, embassy, visa centre, appointment, courier, and payment processor fees are usually non-refundable once incurred. Mileskeeper service-fee refunds after submission are assessed case by case.

Visa decisions. A refusal by an issuing authority does not automatically create a refund because Mileskeeper cannot control government decisions.

Security

Last updated: September 2026

Admin access supports two-factor authentication. Staff access is scoped so non-admin staff see assigned applications and related documents, while administrators can manage the full workspace.

Uploaded files are checked for allowed types and basic file integrity. Optional ClamAV scanning can be enabled in production so suspicious uploads are rejected before staff or customers download them.

Document downloads by staff are recorded in audit logs with user, timestamp, IP address, application context, document context, and file details. Standard create, update, and delete activity is also audited.

Production deployments should serve all traffic over HTTPS, keep document disks private, rotate credentials, run queues and the scheduler, and restrict server and database access to authorized operators.

Found a vulnerability? Please email security@mileskeeper.com with enough detail to reproduce it. We appreciate responsible disclosure.