verifa
Documents
Documents
Terms of Service Privacy Policy DPA Acceptable Use Biometric Policy Cookie Policy Law Enforcement

Biometric Data Policy

Effective date: March 9, 2026

This Biometric Data Policy supplements the Verifa Privacy Policy and explains how we collect, use, store, and destroy biometric data in the course of providing identity verification services.

1. What Biometric Data We Collect

When you complete an identity verification, we derive facial geometry data from the selfie photograph you provide. This consists of a mathematical representation of the spatial relationships between facial features (e.g., distance between eyes, jawline contour) and is classified as biometric data under applicable law, including the Illinois Biometric Information Privacy Act (BIPA).

We do not collect fingerprints, voiceprints, iris scans, or any biometric data other than facial geometry.

2. Purpose

We collect and use facial geometry data for a single, limited purpose: comparing your selfie to the photo on your government-issued ID to verify that you are the person depicted on the document. This comparison produces a numerical similarity score used to determine whether your identity can be verified.

We do not use biometric data for:

  • Surveillance or tracking
  • Advertising or marketing
  • Building facial recognition databases
  • Profiling or behavioral analysis
  • Any purpose other than the identity verification you initiated

3. Consent

We collect biometric data only after you provide informed, written consent through our verification interface. Before any biometric data is derived, you are presented with a clear disclosure explaining:

  • What biometric data will be collected (facial geometry from your selfie)
  • The specific purpose of collection (comparison with your ID photo)
  • How long the data will be retained
  • That you may decline (though this may prevent you from completing verification)

You must affirmatively check a consent box acknowledging these terms before the verification process can proceed. No biometric data is derived or stored until consent is recorded.

4. No Third-Party Disclosure

We do not sell, lease, trade, or otherwise disclose your biometric data to any third party. All face matching is performed within Verifa's own infrastructure. Selfie images may be analyzed by authorized subprocessors for fraud detection (e.g., deepfake detection). See our subprocessors page for the current list.

Biometric data may only be disclosed without consent if required by a valid legal obligation such as a court order, subpoena, or warrant.

5. Storage and Security

Biometric data is protected using the following measures:

  • Encryption at rest: facial geometry data is encrypted using AES-256 before storage
  • Encryption in transit: all data transmission uses HTTPS/TLS 1.2+
  • Access controls: biometric data is accessible only to authorized verification systems — no human operators access raw biometric data during normal operations
  • Isolation: biometric data is stored separately from other personal information and is logically isolated per Customer

6. Retention and Destruction

Biometric data is retained for the shorter of:

  • The retention period configured by the Customer who initiated the verification (default: 90 days), or
  • The period necessary to fulfill the purpose for which it was collected

Once the retention period expires, biometric data is permanently destroyed by securely deleting the encrypted records and associated encryption keys. Destruction is irreversible.

You may request early destruction of your biometric data at any time by contacting us or by having the Customer submit a deletion request through our API. Biometric data will be destroyed within 30 days of a valid request.

7. Your Rights

You have the right to:

  • Decline consent: you may choose not to provide biometric data (this will prevent identity verification from completing)
  • Request deletion: ask us to destroy your biometric data before the retention period expires
  • Access information: request confirmation of whether we hold biometric data about you
  • Lodge a complaint: contact your local data protection authority

8. Illinois Residents (BIPA)

If you are an Illinois resident, your rights under the Biometric Information Privacy Act (740 ILCS 14) are fully respected. Specifically:

  • We obtain your informed, written consent before collecting biometric data
  • We disclose the purpose and retention period before collection
  • We do not sell, lease, trade, or otherwise profit from your biometric data
  • We store, transmit, and protect biometric data using a standard of care equal to or exceeding our protection of other confidential information
  • We destroy biometric data when the initial purpose has been satisfied or within 3 years of last interaction, whichever occurs first

9. Changes to This Policy

We may update this Biometric Data Policy from time to time. Material changes will be communicated through the consent screen at the time of verification.

10. Contact Us

Verifa — Privacy

Email: privacy@withverifa.com