Privacy Policy
Last updated: 3 October 2026
This Privacy Policy explains how Citizenship Shop collects, uses, shares and protects your personal data when you use citizenshipshop.com (the “Site”), contact us, or reserve a program with us. It also explains your rights under the EU General Data Protection Regulation (GDPR) and other data protection laws that apply.
1. Who we are
The data controller is Ajax Software LLC, trading as Citizenship Shop (“we”, “us”), Ankerköz 2-4, 1061 Budapest, Hungary. For any privacy question or request, email [email protected] with “Privacy” in the subject line.
2. Data we collect
Information you give us:
- Contact enquiries: your name, email address, phone or WhatsApp number, and the content of your message.
- Brochure requests: your name, email address, phone number, nationality, delivery address, the programs you are interested in and any delivery notes.
- Client account: your name, email address and password (stored in hashed form).
- Pre-eligibility form: your full name as it appears in your passport, date of birth, nationalities, country of residence, phone number, budget, source of funds, approximate net worth, timeline, and any notes you add.
- Family members: the relationship and age of each family member you include in your application.
- Due diligence answers: whether any applicant has a criminal record or pending investigation, has been refused a visa or citizenship, or is a politically exposed person.
- Application documents you later send to your advisor, such as passports, civil documents, bank statements and proof of funds.
- Communications with us by email, WhatsApp, Signal or phone.
Payment information: Stripe processes reservation payments. We receive the payment status, amount and reference. We never see or store your full card number.
Technical data: when you visit the Site, our servers and Cloudflare record your IP address, browser type, the pages you request and the time of each request. We use this for security and to keep the Site running. We do not use advertising or analytics trackers, and we do not build marketing profiles from your browsing.
Criminal record answers relate to criminal offences and are protected by stricter rules under the GDPR. We process them only because due diligence is required by law and by the program. Your supporting documents may reveal other sensitive data. We process that data only where it is needed for your application and permitted by law.
3. How we use your data and our legal bases
- To send you the brochures and information you request by courier and email. Legal basis: steps you ask us to take before entering into a contract.
- To answer enquiries and give you a free consultation. Legal basis: steps you ask us to take before entering into a contract.
- To run your account and process reservations and payments, assess your eligibility, assign an advisor and prepare your application. Legal basis: performance of our contract with you.
- To carry out identity, anti-money-laundering, sanctions and PEP checks, and to keep the records the law requires. Legal basis: legal obligation.
- To send service emails, such as account, order, payment, reminder and status updates. Legal basis: contract. We also rely on our legitimate interest in reminding you about an unpaid reservation.
- To protect the Site against spam, fraud and abuse. Legal basis: legitimate interest.
- To send program news or offers. Legal basis: your consent, or our legitimate interest where you are already a client. You can opt out at any time.
4. Who we share your data with
We share only what is needed for the service you asked for:
- Program partners for your chosen program: government-authorised agents, approved developers, fund managers, banks, law firms and due diligence providers.
- Government authorities that receive and decide your application.
- Service providers that act on our behalf:
- Amazon Web Services (website hosting),
- Cloudflare (content delivery, security and Turnstile spam protection),
- Stripe (payments),
- Brevo (email delivery),
- DHL or FedEx (delivery of brochures you request – they receive your name, delivery address, phone number and email), and
- WhatsApp or Signal, when you choose to contact us that way.
- Authorities, courts or professional advisers where the law requires it, or where we need to establish, exercise or defend legal claims.
- A buyer or successor of our business, if our business is ever transferred. Your data would stay protected by this Policy.
We do not sell your personal data.
5. International transfers
Many programs are run outside the European Economic Area, for example in the Caribbean, Pacific, Middle East and Asia. Applying to them means sending your data to the government and partners in that country. Some of our service providers may also process data outside the EEA. Where a country has no EU adequacy decision, we rely on Standard Contractual Clauses. Where a transfer is needed to carry out the application you asked for, we may instead rely on its necessity for your contract.
6. How long we keep your data
- Enquiries that do not lead to a reservation: up to 2 years after our last contact.
- Client accounts, orders and applications: for as long as your account is active. After that, for the period required by anti-money-laundering, accounting and tax law, generally 8 years after our relationship ends.
- Server and security logs: normally no more than 12 months.
7. How we protect your data
We protect your data with:
- encrypted connections (HTTPS),
- hashed passwords,
- access controls that limit client data to the staff and advisors working on your case, and
- regular backups.
No internet system is completely secure. If a data breach is likely to put your rights at risk, we will notify you and the supervisory authority as the law requires.
8. Cookies
We use only cookies that the Site needs to work:
- cshop_cart: remembers the programs you add to your cart.
- cshop_nid: a random session identifier that lets us show you form messages, such as sign-in errors. It is deleted when you close your browser.
- WordPress login cookies (wordpress_logged_in_…, wordpress_sec_…): keep you signed in to your client account.
- Cloudflare security cookies (for example __cf_bm) and Cloudflare Turnstile: protect the Site against bots and abuse.
We do not use advertising or tracking cookies. You can block or delete cookies in your browser settings. If you do, the cart and sign-in will stop working. External services you choose to open, such as WhatsApp, Google Drive (for our licence documents) or Stripe Checkout, apply their own cookie and privacy policies.
9. Your rights
Subject to the conditions in the law, you have the right to:
- access your personal data and get a copy of it,
- correct inaccurate data,
- have your data erased,
- restrict how we process it,
- object to processing based on our legitimate interests, and to direct marketing at any time,
- receive data you gave us in a portable format, and
- withdraw your consent at any time. Withdrawal does not affect processing that took place before it.
To exercise any of these rights, email [email protected]. We will reply within one month. We may need to verify your identity first. Some records must be kept by law even if you ask us to delete them. If so, we will explain which ones.
You may also complain to a supervisory authority. In Hungary this is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), Falk Miksa utca 9-11, 1055 Budapest, naih.hu. You can also complain to the authority in your own country.
10. Children
The Site is intended for adults. Data about children is collected only when a parent or legal guardian includes the child as a family member in an application. That parent or guardian provides the data and is responsible for it.
11. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date at the top shows the current version. If we make significant changes, we will tell account holders by email.
12. Contact
Ajax Software LLC (Citizenship Shop), Ankerköz 2-4, 1061 Budapest, Hungary
Email: [email protected]
WhatsApp / Signal: +36 70 550 4957