Who We Are
EB5Visa.io is operated by Bluecode Inc., a Delaware corporation ("we," "us," or "our"). We operate an online marketplace connecting EB-5 investors with Regional Centers, immigration attorneys, real estate developers, securities attorneys, migration agents, and broker-dealers.
Data We Collect
We collect data that you provide directly and data generated through your use of the platform.
All Users
- Full name, email address, handle, and password (stored as a cryptographic hash)
- Profile information you choose to provide (bio, location, profile photo)
- Content you post (posts, comments, messages) — including content moderation scan results
- Usage data: pages visited, features used, session duration, device and browser type
- IP address and approximate geographic location
- Marketing attribution data (UTM parameters) if you arrive via a marketing link
Investors (additional)
- Investment capacity range (self-reported)
- Source of funds declaration (self-reported; e.g., business income, real estate sale, gift, loan)
- Accredited investor self-certification status
- Outreach communication preference (
outreach_opt_in) - Project inquiry history and saved projects
Regional Centers, Developers, Attorneys, Agents, Broker-Dealers (additional)
- Professional credentials: bar admission numbers, USCIS designation IDs, FINRA CRD numbers, licensing jurisdictions
- Organization name, logo, and entity type
- Verification documents uploaded for identity and credential verification
- Team member information (for multi-user organizations)
- Project listing details, offering documents, and financial projections
- Booking URLs and contact preferences for investor inquiries
Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data on the following legal bases under GDPR Article 6:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Platform features and communication | Contract performance (Art. 6(1)(b)) |
| SEC Shield content scanning | Legitimate interest — regulatory compliance (Art. 6(1)(f)) |
| Compliance audit trail (Blackbox) | Legal obligation — SEC recordkeeping (Art. 6(1)(c)) |
| Investment calculator lead capture | Consent (Art. 6(1)(a)) — withdrawable at any time |
| RC outreach communications | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Analytics and platform improvement | Legitimate interest (Art. 6(1)(f)) |
| Feed personalization (implicit engagement signals) | Legitimate interest — platform improvement (Art. 6(1)(f)) |
How We Use Your Data
- To provide, maintain, and improve the platform
- To verify your identity and professional credentials
- To scan content for regulatory compliance (SEC Shield) — content is analyzed for prohibited language before publication
- To facilitate connections between investors and EB-5 professionals
- To send transactional emails (account verification, inquiry notifications, security alerts)
- To send RC outreach communications if you have enabled
outreach_opt_inin your settings - To detect, investigate, and prevent fraud and platform abuse
- To maintain compliance audit logs as required by SEC recordkeeping rules
- To analyze aggregate, anonymized usage patterns for product improvement
Investment Calculator & Cost Estimate Lead Capture
Our free Investment Cost Calculator collects your first name, email address, country of residence, and the investment configuration inputs you select during the calculator workflow (e.g., investment type, attorney tier, family size, source of funds complexity).
How We Use This Data
- Delivering your estimate: We use your inputs to generate and display your personalized EB-5 cost breakdown immediately.
- Saving your results: Your estimate is saved to our database so you can retrieve it after creating an account.
- Follow-up communications: With your explicit consent (given at the point of form submission), we may send you relevant EB-5 educational content, platform updates, and information about EB-5 investment opportunities.
- Product improvement: Aggregate, anonymized calculator usage data is used to improve our estimation models.
Your Consent Rights
You give explicit consent at the point of submitting the calculator gate form. This consent covers the delivery of your estimate and follow-up EB-5 updates. You may withdraw consent at any time by:
- Clicking "Unsubscribe" in any email we send you
- Navigating to Settings → Privacy if you have an account
- Emailing [email protected] with subject "Unsubscribe"
Data Not Collected
The Investment Calculator does not collect your actual investment amount, banking or financial account information, government identification numbers, or any information about specific investment projects. All figures are educational estimates only.
Compliance Audit Trail (Blackbox)
The Blackbox Audit Trail records the following types of events:
- Registration and profile changes for Professional users (Regional Centers, attorneys, agents)
- Investor inquiry creation, status changes, and messaging activity
- Content moderation actions taken by administrators
- Administrator identity and action type for every moderation decision
- Organization membership changes (invites, role changes, removals)
Audit logs are retained for 7 years from the date of recording, in accordance with SEC recordkeeping requirements under Exchange Act Rule 17a-4. These logs are immutable — they cannot be modified or deleted outside of a formal legal retention adjustment process.
Access to audit logs is restricted to super-administrators with verified credentials. Audit logs may also be disclosed to regulatory authorities (SEC, USCIS, FINRA) in response to valid legal requests.
Data Sharing & Disclosure
We do not sell your personal data. We may share your data only as follows:
- Service providers (data processors): Supabase (database and authentication), Vercel (hosting), Sentry (error monitoring). All operate under data processing agreements.
- Other platform users: Your public profile information (name, handle, role, bio) is visible to other registered users. Investor inquiry details are shared with the Regional Center you contact.
- Legal compliance: We will disclose data to USCIS, the SEC, FINRA, or other governmental authorities when required by law, court order, or valid legal process.
- Business transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred to the acquiring entity, subject to equivalent privacy protections.
Data Retention
| Data Category | Retention Period |
|---|---|
| Active account data | Duration of account + 30 days after deletion request |
| Calculator lead capture data | 2 years from date of submission, or until you unsubscribe |
| Compliance audit logs (Blackbox) | 7 years (SEC recordkeeping requirement) |
| Content moderation scan logs | 2 years |
| Marketing attribution data | 90 days |
| Feed engagement signals (impressions, dwell time, profile clicks) | 90 days, then anonymized for aggregate modeling |
| Analytics data (aggregated, anonymized) | Indefinite (not personal data) |
Your Privacy Rights
GDPR Rights (EEA / UK residents)
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate personal data
- Right to erasure: Request deletion of your data (subject to legal retention obligations — audit logs cannot be erased within the legal retention period)
- Right to portability: Receive your data in a machine-readable format
- Right to object: Object to processing based on legitimate interest
- Right to withdraw consent: Withdraw consent for outreach communications at any time via Settings → Privacy
CCPA Rights (California residents)
- Right to know: Request disclosure of personal data collected, used, and shared
- Right to delete: Request deletion of your data (subject to legal exceptions)
- Right to opt out of sale: We do not sell personal data
- Right to non-discrimination: We will not discriminate against you for exercising CCPA rights
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing certain requests.
RC Outreach Communications
If you are a registered investor, you may be contacted by Regional Centers with information about EB-5 investment opportunities if you have enabled the outreach preference in your account settings (outreach_opt_in = true).
This consent is optional and not required to use the platform. You may withdraw consent at any time by navigating to Settings → Privacy or by contacting us at [email protected]. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Children
EB5Visa.io is intended for users aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected personal data from a child under 18, we will delete it promptly. If you believe we have inadvertently collected such data, contact us at [email protected].
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by updating the Effective Date at the top of this page. Continued use of the platform after an updated policy takes effect constitutes your acceptance of the changes.
Feed Personalization & Content Recommendations
What Signals We Collect
When you use the EB5Visa.io feed, we collect both explicit and implicit engagement signals to understand which content is most relevant to you.
| Signal Type | How It Is Collected | Example |
|---|---|---|
| Like | Explicit — you click the Like button | Liking a project update post |
| Comment | Explicit — you submit a comment | Commenting on a Regional Center post |
| Save | Explicit — you save a post via the menu | Saving an attorney's guide for later |
| Share | Explicit — you share a post | Sharing an EB-5 insight article |
| Impression | Implicit — post appears in your viewport | Post scrolled into view on your screen |
| Dwell time | Implicit — time post is visible in your viewport (≥2s) | Pausing to read a project post for 10+ seconds |
| Expand | Implicit — you click "Read more" on a post | Expanding a long article post |
| Profile click | Implicit — you click an author's profile from their post | Visiting an immigration attorney's profile after reading their post |
| Post link click | Implicit — you click an external link within a post | Clicking a USCIS link shared in a post |
| Hide post | Explicit — you choose "Hide this post" from the post menu | Hiding a post you've already seen |
How These Signals Are Used
- Feed ranking:Signals are used to compute a relevance score for each post. Posts you are likely to find valuable (based on past engagement patterns) are ranked higher in the “For You” sort mode.
- Interest cluster inference:Your engagement patterns are used to infer broad interest categories (e.g., “Project Discovery”, “Compliance Intelligence”, “Investor Education”). These clusters influence which types of content are prioritized for you. They are not shared with other users or third parties.
- Connection strength: Your interaction history with other users (comments on their posts, following them, inbox conversations) is used to weight content from users you have a higher connection strength with. This keeps your feed focused on the professionals most relevant to your EB-5 journey.
- Platform improvement: Aggregate, anonymized engagement data is used to improve our content ranking models. No individual-level data is shared externally.
What We Do NOT Do
- We do not sell or share your engagement signals with advertisers or third parties.
- We do not use engagement signals to make automated decisions that produce legal or similarly significant effects on you.
- We do not use your engagement data to infer or store sensitive categories of data (health, political views, religion, etc.).
- Personalization signals are scoped to the EB5Visa.io feed only and are not used to target you off-platform.
Legal Basis (GDPR)
Feed personalization is processed on the basis of our legitimate interests (GDPR Art. 6(1)(f)) to improve the relevance and quality of your platform experience. We have conducted a Legitimate Interest Assessment (LIA) and concluded that this processing does not override your fundamental rights, given the limited sensitivity of the data, the EB-5 professional context of the platform, and the controls available to you.
Your Controls
- Default sort: The feed defaults to Recent(chronological). “For You” personalization is only applied when you explicitly select the “For You” sort mode.
- Hide a post:You can hide individual posts from your feed using the “Hide this post” option in the post menu. Hidden posts are stored locally and do not affect the post\'s ranking for other users.
- Right to object (GDPR): EEA/UK residents may object to personalization processing at any time by emailing [email protected]with subject “Object to Feed Personalization.” We will cease personalization processing within 30 days.
- Data deletion: All feed engagement signals linked to your account are deleted within 30 days of account deletion. Signals are retained for a maximum of 90 days from collection, then anonymized for aggregate platform modeling.