Privacy Policy

Your privacy matters. Learn how O1DMatch collects, uses, and safeguards your personal information.

Last updated: February 17, 2026

1. Introduction

O1DMatch ("we," "our," or "us") operates a platform that connects individuals with extraordinary ability ("Talent") with employers seeking to sponsor O-1 visas ("Employers"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you access or use our website, applications, and services (collectively, the "Platform").

By using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Platform.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, phone number, password, and profile photo.
  • Professional Information: Job title, employer, skills, work history, education, and professional achievements.
  • Immigration Documents: Visa petition documents, evidence of extraordinary ability, exhibit packets, interest letters, and supporting materials uploaded for scoring or case management.
  • Payment Information: Billing address and payment method details processed securely through Stripe. We do not store full credit card numbers on our servers.
  • Communications: Messages, feedback, and support requests you send to us.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, actions taken, and time spent on the Platform.
  • Device Information: Browser type, operating system, device identifiers, and screen resolution.
  • Log Data: IP address, access times, referring URLs, and error logs.
  • Cookies: Small data files stored on your device (see Section 8).

2.3 Information from Third Parties

  • Authentication providers (e.g., Google OAuth) when you sign in with a third-party account.
  • Payment processors (Stripe) for transaction verification.
  • E-signature services (SignWell) for document signing status.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Platform and its features.
  • Match Talent with Employers based on skills, experience, and visa eligibility criteria.
  • Process and score visa petition documents using our AI-powered scoring tools to evaluate O-1 eligibility.
  • Generate exhibits, petition materials, and interest letters for immigration case support.
  • Process payments, manage subscriptions, and administer credit systems (e.g., re-score credits).
  • Send transactional emails (account verification, password resets, interest letter approvals) and, with your consent, marketing communications.
  • Detect fraud, abuse, and security threats to protect users and the Platform.
  • Comply with legal obligations and respond to lawful requests.
  • Conduct analytics and research to improve our services.

4. Data Sharing & Disclosure

We do not sell your personal information. We may share data with:

  • Employers (for Talent users): Your profile information and scoring results may be shared with Employers you match with or express interest in, only to the extent necessary for the matching and sponsorship process.
  • Service Providers: Trusted third parties that help us operate the Platform, including Supabase (database and authentication), Stripe (payments), Vercel (hosting), SignWell (e-signatures), and Google Drive (document management).
  • AI Scoring Services: Documents you upload for petition scoring are processed by our AI scoring API to evaluate O-1 eligibility criteria. These documents are transmitted securely and used solely for scoring purposes.
  • Legal & Immigration Professionals: When you engage attorneys or agencies through the Platform, relevant case information may be shared with them at your direction.
  • Legal Requirements: We may disclose information if required by law, court order, or governmental authority, or to protect our rights, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Row-level security (RLS) policies ensuring users can only access their own data.
  • Secure authentication with encrypted password storage and session management.
  • Server-side API key management — sensitive credentials like scoring and payment API keys are never exposed to the browser.
  • Regular security reviews and monitoring for vulnerabilities.

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Specifically:

  • Account Data: Retained until you delete your account.
  • Scoring Sessions & Documents: Retained for the duration of your subscription. You may delete individual scoring sessions at any time.
  • Payment Records: Retained as required by tax and financial regulations (typically 7 years).
  • Log Data: Automatically purged after 90 days.

Upon account deletion, we will remove your personal information within 30 days, except where retention is required by law.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Portability: Request your data in a portable, machine-readable format.
  • Opt-Out: Unsubscribe from marketing emails at any time using the link in each email.
  • Restrict Processing: Request that we limit how we use your data in certain circumstances.

To exercise any of these rights, contact us at privacy@o1dmatch.com. We will respond within 30 days.

California Residents (CCPA): You have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell personal information.

EU/UK Residents (GDPR): You have additional rights including the right to object to processing, withdraw consent, and lodge a complaint with a supervisory authority.

8. Cookies & Tracking

We use the following types of cookies:

TypePurposeDuration
EssentialAuthentication, security, session managementSession
FunctionalUser preferences, dashboard settings1 year
AnalyticsUsage patterns, feature adoption, performance2 years

You can control cookies through your browser settings. Disabling essential cookies may affect Platform functionality.

9. International Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses where required.

10. Children\u2019s Privacy

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the new policy on this page with an updated "Last updated" date, and for significant changes, by sending an email notification. Your continued use of the Platform after changes take effect constitutes acceptance of the revised policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

O1DMatch

Email: privacy@o1dmatch.com

Contact Page: o1dmatch.com/contact