This Privacy Policy explains how VerifiNow Inc. (“VerifiNow,” “we,” “our,” or “us”) collects, uses, processes, stores, and protects personal information in connection with our identity verification, fraud prevention, biometric authentication, compliance services, website, and related services.
Personal information processed through VerifiNow may include sensitive information such as government-issued identity document data, biometric information, and, when enabled by a VerifiNow Customer, precise device location information.
1. Introduction
VerifiNow provides identity verification, biometric authentication, fraud prevention, and compliance services to businesses and organizations (“Customers”) and their end users (“Individuals”).
When an Individual completes a verification initiated by one of our Customers, VerifiNow generally processes personal information on behalf of and according to the instructions of that Customer.
The Customer determines the purpose of the verification, the applicable verification workflow, certain information that will be collected, and the retention requirements for verification records.
This Privacy Policy applies to:
Individuals who complete an identity verification through VerifiNow;
Visitors to getverifinow.com; and
Business contacts who interact directly with VerifiNow.
2. Information We Collect
2.1 Identity Document Data
When identity document verification is part of a verification workflow, we may process:
Images of government-issued identity documents;
Information extracted from the document, such as name, date of birth, address, document number, and expiration date;
Document authenticity and validation signals;
AAMVA barcode or ICAO MRZ information, where applicable; and
Document type and country or jurisdiction of issuance.
Identity document images and related verification records may be retained according to the retention requirements established by the Customer that initiated the verification.
2.2 Biometric Data
Biometric information may be processed as part of identity verification or authentication services and may be subject to heightened legal protections.
Depending on the verification workflow, VerifiNow may process:
Facial images captured during a selfie or live verification;
Biometric comparison scores;
Liveness detection signals and results; and
Presentation attack detection signals used to identify potential photo, video, replay, mask, deepfake, or other spoofing attempts.
Biometric images and related verification records may be retained according to the requirements established by the Customer that initiated the verification.
See Section 6 for additional information regarding our biometric data practices.
2.3 Verification Session and Location Data
During a verification session, we may process information including:
Session timestamp and unique session identifier;
Device type, operating system, browser, and IP address;
Approximate location derived from IP address;
Capture quality metrics and retry attempts;
Verification outcome, such as pass, fail, or review;
Confidence scores and other decision-related information; and
Precise device location or GPS information when that capability is enabled by the Customer.
Precise GPS location is not required for every VerifiNow verification.
GPS collection is a configurable feature made available to VerifiNow Customers. Some Customers may choose not to collect precise GPS information. Other Customers may enable GPS collection and may configure it as either optional or required as part of their verification workflow.
When precise location is requested, the Individual’s device or browser may request permission to provide location information. Whether an Individual can complete the applicable verification without providing precise location depends on the requirements established by the Customer that initiated the verification.
For Individuals in California, providing precise GPS location is always optional and is never a condition of completing a verification. See “California Residents” in Section 10.
2.4 Compliance and Screening Data
When applicable to a Customer’s selected services, we may process information related to:
Sanctions and watchlist screening;
Politically Exposed Person (PEP) screening;
Adverse media screening;
Employment verification;
Income verification; and
KYC or eKYC decisioning and associated audit records.
2.5 Customer and Business Contact Data
We may collect:
Name and job title;
Business email address and phone number;
Company name, industry, and professional role; and
Communications and engagement history with VerifiNow.
2.6 Website and Platform Usage Data
When you visit our website, we may collect:
IP address and approximate location;
Pages visited and time spent on pages;
Referral source;
Browser and device information; and
Cookie and analytics information as described in Section 9.
3. How We Use Personal Information
We may use personal information to:
Authenticate government-issued identity documents;
Compare a captured facial image to the photograph contained on an identity document;
Conduct liveness detection and confirm physical presence;
Detect document forgery, presentation attacks, injection attacks, deepfakes, and other suspected fraud;
Complete identity verification and authentication workflows;
Process Customer-configured location information when GPS collection has been enabled;
Perform KYC or eKYC decisioning and AML-related screening on behalf of Customers;
Confirm employment or income information where applicable;
Generate verification results and associated audit records;
Maintain verification records in accordance with Customer instructions;
Monitor platform security and investigate potential security incidents;
Operate, maintain, and improve our services; and
Communicate with Customers and business contacts.
VerifiNow does not sell personal information.
VerifiNow does not use personal information for advertising within the identity verification process.
VerifiNow does not use biometric information to train general-purpose artificial intelligence models without explicit written consent.
4. Legal Basis for Processing
Where applicable law requires a legal basis for processing personal information, the applicable basis depends on the verification service, the Customer’s use of VerifiNow, and the jurisdiction in which the processing occurs.
Depending on the circumstances, processing may be based on:
Consent;
Performance of a contract;
Legitimate interests;
Compliance with legal or regulatory obligations; or
Another basis permitted by applicable law.
When VerifiNow processes personal information on behalf of a Customer, the Customer is responsible for determining the appropriate legal basis for the processing it instructs VerifiNow to perform.
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, biometric data used to uniquely identify an Individual is a special category of personal data under Article 9. It is processed only with the Individual’s explicit consent or under another condition permitted by Article 9(2).
5. Data Sharing and Disclosure
5.1 With Customers
We provide verification results, applicable session information, and other verification records to the Customer that initiated the verification.
The Customer controls its use and retention of information generated or collected through its use of VerifiNow, subject to applicable law and its agreements with VerifiNow.
5.2 With Service Providers and Sub-processors
We may engage service providers and sub-processors to support functions such as:
Cloud infrastructure;
Document authentication;
Identity and database verification;
Sanctions and compliance screening;
Employment and income verification; and
Security monitoring.
Where required, these providers are subject to contractual obligations governing the protection and permitted use of personal information.
5.3 Legal and Regulatory Disclosures
We may disclose personal information when required by applicable law, valid legal process, regulatory requirements, or where otherwise permitted by law.
5.4 Corporate Transactions
Personal information may be transferred as part of a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction, subject to applicable legal requirements.
5.5 No Sale of Personal Information
VerifiNow does not sell, rent, lease, or trade personal information, including biometric information and government-issued identity information, to third parties for commercial purposes.
6. Biometric Data — Special Protections
VerifiNow may process biometric information as part of identity verification or authentication services performed on behalf of our Customers.
Collection and Purpose
Facial information may be captured to:
Confirm that an Individual is physically present;
Compare the Individual to the photograph associated with a government-issued identity document;
Detect presentation attacks, spoofing, deepfakes, or other attempted impersonation; and
Produce verification and liveness results.
Retention of Biometric and Verification Records
VerifiNow Customers control the retention requirements applicable to verification records processed on their behalf.
Verification records may include:
Government-issued identity document images;
Selfie or facial images captured during verification;
Extracted identity information;
Biometric comparison results;
Liveness results;
Verification decisions;
Location information, where collected;
Session information; and
Related audit records.
Retention periods may vary from Customer to Customer based on the Customer’s business requirements, policies, contractual obligations, and applicable legal or regulatory requirements.
VerifiNow processes, retains, and deletes these records in accordance with the instructions and retention requirements of the applicable Customer, subject to applicable law.
Illinois Biometric Retention Schedule
For biometric identifiers and biometric information of Individuals in Illinois, VerifiNow maintains the following retention schedule and destruction guidelines under the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14:
VerifiNow permanently destroys biometric identifiers and biometric information when the initial purpose for collecting or obtaining them has been satisfied, or within 3 years of the Individual’s last interaction with VerifiNow, whichever occurs first;
A Customer’s retention settings cannot extend the retention of this biometric data beyond that period; and
VerifiNow retains biometric data beyond this schedule only if required by a valid warrant or subpoena issued by a court of competent jurisdiction.
Security
VerifiNow uses administrative, technical, and organizational safeguards designed to protect biometric and other sensitive personal information from unauthorized access, use, alteration, or disclosure.
No Sale of Biometric Information
VerifiNow does not sell, lease, or trade an Individual’s biometric information.
Limited Disclosure
Biometric information may be disclosed only as necessary to provide the applicable verification service, to authorized service providers supporting that service, at the direction of the applicable Customer, or where disclosure is required or permitted by law.
7. Data Retention and Deletion
7.1 Customer-Controlled Verification Records
The Customer that initiated the verification controls the retention of verification records processed on its behalf.
These records may include:
Identity document images;
Selfie or facial images;
Identifying information;
Biometric and liveness results;
Verification outcomes;
Location information, where collected;
Session information; and
Related audit records.
Customers may establish different retention periods based on their business, security, compliance, contractual, and regulatory requirements.
VerifiNow retains or deletes Customer-controlled verification records in accordance with the applicable Customer’s instructions and applicable law.
Retention of biometric data of Individuals in Illinois is also subject to the Illinois Biometric Retention Schedule in Section 6.
7.2 End-User Access, Correction, and Deletion Requests
Individuals who wish to request access to, correction of, or deletion of identifying information or verification records—including images captured during the verification process—should submit their request to the Customer or organization that initiated the verification.
Because that Customer controls the applicable verification records and determines their retention requirements, the Customer is generally responsible for evaluating and responding to the Individual’s request in accordance with applicable law.
Deletion requests may be subject to legal, regulatory, contractual, fraud-prevention, dispute-resolution, security, or recordkeeping requirements that permit or require certain information to be retained.
7.3 VerifiNow Business Records
Information that VerifiNow collects for its own business purposes, such as Customer account, contract, billing, security, and business contact information, may be retained for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, accounting, security, or contractual obligations.
8. Data Security
VerifiNow maintains administrative, technical, and organizational safeguards designed to protect personal information.
These safeguards may include:
Encryption of sensitive information in transit and at rest;
Role-based access controls;
Restricted access to sensitive systems;
Multi-factor authentication for applicable privileged access;
Security testing and vulnerability management;
Security monitoring;
Incident response procedures; and
Security requirements for applicable service providers and sub-processors.
Where VerifiNow processes personal data as a processor, we notify the affected Customer without undue delay after becoming aware of a personal data breach. Where VerifiNow is the controller and the GDPR or UK GDPR applies, we notify the competent supervisory authority within 72 hours where required.
No method of electronic transmission or storage is completely secure. Although VerifiNow uses safeguards designed to protect personal information, absolute security cannot be guaranteed.
9. Cookies and Tracking Technologies
We may use essential, analytics, preference, and, where appropriate and consented to, marketing cookies on getverifinow.com.
We do not use advertising tracking technologies within the identity verification workflow.
Website visitors may manage cookie preferences through available website controls or their browser settings.
10. Individual Privacy Rights
Depending on applicable law, Individuals may have rights concerning their personal information, including rights to:
Request access to personal information;
Request correction of inaccurate information;
Request deletion of personal information;
Obtain a copy of certain personal information;
Restrict or object to certain processing activities; and
Exercise other rights available under applicable privacy or biometric privacy laws.
Requests Related to Customer Verification Records
If your personal information was collected because you completed a VerifiNow verification for a bank, employer, healthcare provider, educational institution, retailer, government entity, or another organization, that organization is the VerifiNow Customer responsible for the applicable verification records.
Requests to access, correct, or delete those records—including identity document images and selfie or facial images—should be submitted directly to the organization that initiated the verification.
The Customer will determine how to respond to the request based on applicable law and its own retention obligations.
Where appropriate, VerifiNow will assist Customers in responding to valid privacy requests relating to information VerifiNow processes on their behalf.
Information Controlled Directly by VerifiNow
For privacy requests concerning personal information VerifiNow collects directly for its own business purposes, contact:
We will process applicable requests in accordance with applicable law.
California Residents
Some of the information described in this Privacy Policy is “sensitive personal information” under the California Consumer Privacy Act, as amended (CCPA), including government-issued identification numbers, biometric information, and precise geolocation.
Precise geolocation is optional in California. For Individuals in California, providing precise GPS location is always optional. An Individual may decline the device or browser location request, and declining will not by itself prevent the Individual from completing the verification.
VerifiNow uses and discloses sensitive personal information only to provide the verification and related services requested, to detect and prevent fraud and security incidents, to comply with law, and for other purposes permitted by the CCPA. VerifiNow does not use sensitive personal information to infer characteristics about Individuals.
Subject to the CCPA, California residents have the right to:
Know what personal information is collected, used, and disclosed about them;
Request deletion of personal information;
Request correction of inaccurate personal information;
Opt out of the sale or sharing of personal information (VerifiNow does not sell personal information);
Limit the use and disclosure of sensitive personal information; and
Not receive discriminatory treatment for exercising these rights.
Requests about verification records should be submitted to the Customer that initiated the verification, as described above. For personal information VerifiNow controls directly, email privacy@verifinow.io. We will verify the requester’s identity before responding, and an authorized agent may submit a request on a California resident’s behalf.
Individuals in the EEA, UK, and Switzerland
Where the GDPR, the UK GDPR, or Swiss data protection law applies, you have the right to access, rectify, and erase your personal data; to restrict or object to its processing; to data portability; and, where processing is based on consent, to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
When VerifiNow processes personal data on behalf of a Customer, the Customer is the controller and VerifiNow is its processor. Requests about those records should be sent to the Customer, and VerifiNow will assist the Customer in responding.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, where you work, or where the alleged infringement took place.
You may contact our Data Protection Officer at dpo@verifinow.io or send GDPR inquiries to gdpr@verifinow.io.
11. International Data Transfers
VerifiNow is headquartered in the United States.
Where personal information is transferred internationally, VerifiNow uses safeguards appropriate to the circumstances and as required by applicable law.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, VerifiNow relies on the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), and equivalent mechanisms, as applicable.
Customers may also establish data residency, hosting, or processing requirements through their agreements with VerifiNow.
12. Children’s Privacy
VerifiNow’s services are not directed to children for independent use.
Where a Customer uses VerifiNow in connection with an Individual under the age of 18, the Customer is responsible for ensuring that the verification and associated processing are authorized and permitted under applicable law.
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our services, technology, data practices, or applicable legal requirements.
When we make changes, we will update the Last Updated date at the top of this Privacy Policy and provide additional notice where required by applicable law.
14. Contact Information
For questions regarding this Privacy Policy or VerifiNow’s privacy practices, contact:
| Privacy Inquiries | privacy@verifinow.io |
|---|---|
| Data Protection Officer | dpo@verifinow.io |
| GDPR / EU Inquiries | gdpr@verifinow.io |
| Mailing Address | VerifiNow Inc. Attn: Privacy Team 3579 E Foothill Blvd #289 Pasadena, CA 91107 |