Biometric Information Policy
- Version
- 1.0
- Effective
- August 25, 2026
- Last updated
- August 25, 2026
1. Why this policy exists
Some U.S. laws require any company that collects, captures, or otherwise obtains biometric identifiers or biometric information — or that causes a vendor to do so for its own purposes — to publish a written policy establishing a retention schedule and destruction guidelines. TraIDCred initiates identity verification that involves biometric processing performed by Stripe, Inc. ("Stripe"), and publishes this policy so that its position, its retention schedule, and its destruction practices are public, specific, and checkable — without overstating what TraIDCred actually holds (see §2: TraIDCred holds no biometric data).
2. What TraIDCred does and does not possess
When TraIDCred asks a person to verify their identity, the verification is performed by Stripe, using Stripe Identity, on Stripe-hosted pages. Stripe collects images of the person's government photo ID and a live selfie, and processes biometric identifiers — a scan of face geometry — to compare the selfie to the ID photo.
TraIDCred never receives, stores, accesses, or possesses: the ID images, the selfie, any facial scan, template, or other biometric identifier or biometric information. TraIDCred's systems hold no API credential capable of retrieving them from Stripe, and TraIDCred performs no biometric processing of any kind anywhere in its Services (including no comparison involving any photograph a business uploads).
What TraIDCred receives and retains from a verification: the verification result (status and timestamps), a machine-readable error code where verification did not succeed, and — on success only — the person's verified first and last name. None of these is a biometric identifier or biometric information.
3. Purpose limitation
Biometric processing is initiated for exactly one purpose: identity verification — establishing that a real person holds the government ID they presented, so that actions taken on TraIDCred (for example, a license-qualifier authorization) are attributable to a verified legal identity. Neither TraIDCred nor, per its instructions and Stripe's terms, the biometric data is used to: advertise, profile, or track anyone; sell or trade any data; or determine anyone's eligibility for credit, insurance, housing, or employment.
4. Notice and written release before collection
Before any TraIDCred-initiated verification that involves biometric processing of a person who is not an account-holding customer (today: the license-qualifier ceremony), TraIDCred presents a Biometric Information Notice on its own pages — stating what will be collected, by whom, for what specific purpose, and under what retention schedule — and obtains that person's affirmative written release, executed by electronic signature, before the verification session is created. The exact notice text, its version, and the release are recorded immutably. Stripe additionally presents its own consent on its own pages before collecting anything. A person who prefers not to proceed may decline without consequence (the qualifier request simply remains unconfirmed).
5. Retention schedule and destruction guidelines
- Biometric identifiers and biometric information (held by Stripe, never by TraIDCred):
Stripe states that the biometric identifiers created to conduct a verification are removed from its systems within one year, and that submitted verification information is typically stored by Stripe for up to three years, under Stripe's own privacy policy (https://stripe.com/privacy).
- TraIDCred's destruction mechanism: TraIDCred's control over Stripe-held verification
data is Stripe's redaction operation (POST /v1/identity/verification_sessions/{id}/redact), which Stripe documents as removing all collected information from the verification session and its related records — irreversibly, with Stripe stating the process may take up to four days to complete once a request is accepted. TraIDCred requests this redaction automatically: a daily scheduled job begins attempting the request about 25 days after the qualifier ceremony concludes (the request is authorized, declined, or revoked — whichever happens first), retries on failure, and escalates internally so that the request is made no later than 30 days after the ceremony concludes, except where a temporary processing state or technical condition prevents Stripe from accepting the request — in which case the daily retries and internal escalation continue until it succeeds. The 30-day commitment describes when TraIDCred requests deletion; when Stripe accepts the request and when Stripe completes the irreversible deletion are Stripe's steps, on Stripe's stated schedule. A ceremony that has not concluded (for example, a verification still in progress) is not redacted while active; its data remains subject to Stripe's own schedule above. Satisfaction of the initial purpose, or three years after the person's last interaction with TraIDCred, whichever occurs first, is the outer bound of this schedule.
- The verification result TraIDCred retains (status, timestamps, verified name — not
biometric data): retained while the verified relationship does work on the Services and handled under the Data Retention Policy; the verified name is cleared whenever a verification stops standing.
- Consent and release records (the notice text, version, and executed release — not
biometric data): retained as legal evidence of authorization, including after revocation or deletion requests to the extent reasonably necessary to prove what was authorized and comply with law.
6. No sale, no trade, no profit
TraIDCred does not — and has nothing with which to — sell, lease, trade, or otherwise profit from any biometric identifier or biometric information. TraIDCred's instructions to Stripe permit use of the collected data only to provide the verification service.
7. Disclosure
TraIDCred discloses no biometric identifier or biometric information to anyone (it possesses none). The business that requested a verification is told only the status and outcome of the process. Stripe's own handling of the data it collects is governed by Stripe's privacy policy and terms.
8. Storage and protection
TraIDCred stores no biometric data, so no TraIDCred storage of it exists to describe. The verification results TraIDCred does hold are protected as described in the Security Overview, at least as protectively as TraIDCred handles its other confidential information. Stripe's storage of what Stripe collects is described in Stripe's own documentation.
9. Questions, revocation, and rights
Contact privacy@traidcred.com — including from an email address with no TraIDCred account — to ask questions, revoke an authorization prospectively, or exercise the privacy rights described in the Privacy Policy §8. To reach Stripe about the data Stripe holds, see Stripe's privacy policy or the Identity Verification Notice.