Identity binding for the AI era Book a Demo →
Legal

Privacy Policy

Effective Date: March 4, 2026  •  Last Updated: March 4, 2026

Important: This Privacy Policy governs the collection, use, storage, and protection of personal information — including biometric data, government-issued identity documents, and financial verification data — processed by VerifiNow Inc. in connection with its identity verification, fraud prevention, and compliance services.

1. Introduction

VerifiNow Inc. (“VerifiNow,” “we,” “our,” or “us”) provides real-time identity verification, biometric binding, fraud prevention, and compliance services to businesses (“Customers”) and their end users (“Individuals”). VerifiNow operates as a data processor on behalf of its Customers in most verification contexts. The Customer who deploys VerifiNow’s services is the data controller responsible for determining the purposes of processing.

This Policy applies to: Individuals who complete identity verification through VerifiNow’s platform; visitors to getverifinow.com; and business contacts who interact with VerifiNow directly.

2. Information We Collect

2.1 Identity Document Data

Images of government-issued identity documents; extracted data fields (name, date of birth, address, document number, expiration date); document authenticity signals (AAMVA barcode, ICAO MRZ); and document classification and country of issuance.

2.2 Biometric Data

⚠ Biometric data is sensitive personal information subject to heightened legal protections. See Section 6 for specific biometric data protections.

Facial images captured during live selfie capture; biometric comparison scores; liveness detection signals and results; and presentation attack detection signals for photo, video, 3D mask, and deepfake attacks.

2.3 Verification Session Data

Session timestamp, duration, and unique session identifier; device type, OS, browser, and IP address; geolocation at country/region level; capture quality metrics and retry attempts; verification outcome (pass/fail/review); and confidence scores and decision rationale.

2.4 Compliance and Screening Data

Sanctions screening results (OFAC, UN, EU, FATF); PEP and adverse media screening results; employment verification data; income verification data; and KYC/eKYC decisioning records and audit trails.

2.5 Customer and Business Contact Data

Name, title, business email, and phone number; company name, industry, and role; and communications and engagement history with VerifiNow.

2.6 Website and Platform Usage Data

IP address and approximate geolocation; pages visited, time on page, and referral source; browser and device type; and cookie and analytics data (see Section 9).

3. How We Use Personal Information

We do not use personal data for advertising.  We do not sell personal data.  We do not use biometric data to train general-purpose AI models without explicit written consent.

4. Legal Basis for Processing

Identity verification
Contract performance; Legitimate interests (fraud prevention)
AML/KYC compliance
Legal obligation (BSA, AML regulations)
Biometric processing
Explicit consent where required; Legitimate interests in fraud prevention
Employment/income verification
Consent; FCRA permissible purpose
Platform security
Legitimate interests
Regulatory record retention
Legal obligation

5. Data Sharing and Disclosure

5.1 With Customers

We share verification results, session records, and compliance outcomes with the Customer who initiated the verification. Customers are responsible for their own use of Individual data.

5.2 With Sub-processors

We engage vetted third-party sub-processors for cloud infrastructure, document authentication, sanctions data, employment/income data, and security monitoring. All sub-processors are bound by data processing agreements requiring equivalent protection.

5.3 Legal and Regulatory Disclosures

We may disclose personal data in response to valid legal process, regulatory examination, or emergency situations involving imminent risk to life or safety. We notify affected Customers of legal requests where permitted by law.

5.4 Corporate Transactions

Personal data may be transferred in a merger, acquisition, or asset sale. We will provide required notice and require successor entities to honor this Policy.

5.5 No Sale of Personal Data

VerifiNow does not sell, rent, lease, or trade personal data — including biometric data, government ID data, or financial verification data — to third parties for commercial purposes under any circumstances.

6. Biometric Data — Special Protections

Illinois (BIPA)
Written consent, retention schedule, destruction policy, no sale, no profit from biometric data
Texas (CUBI)
Informed consent, reasonable security, no sale or disclosure without consent
Washington
Consent, data minimization, Individual rights
EU/EEA (GDPR Art. 9)
Special category data; explicit consent or other Article 9(2) basis required

7. Data Retention

Biometric data
90 days from collection
Identity document images
90 days from collection
Extracted document data fields
1 year
Verification session records
7 years (BSA/AML audit requirement)
KYC/AML screening records
7 years (regulatory requirement)
Employment/income verification records
Per FCRA requirements
Customer account and contract data
Duration of contract + 3 years
Website analytics data
13 months

8. Data Security

9. Cookies and Tracking Technologies

We use essential, analytics, preference, and (with consent) marketing cookies on getverifinow.com. We do not use tracking technologies within the identity verification flow. You may manage cookie preferences through your browser settings.

10. Individual Rights

Access
Request a copy of the personal data we hold about you
Correction
Request correction of inaccurate or incomplete data
Deletion
Request deletion, subject to legal retention requirements
Portability
Request data in a structured, machine-readable format
Restriction/Object
Restrict or object to processing in specified circumstances
Biometric (Illinois/BIPA)
Request deletion, information about practices, and compensation for violations
CCPA (California)
Know, delete, opt out of sale (we don’t sell), correct, non-discrimination
GDPR (EU/EEA/UK)
All rights above plus right to lodge complaint with supervisory authority

To exercise your rights, contact privacy@verifinow.io. We respond within 30 days or as required by applicable law.

11. International Data Transfers

VerifiNow is headquartered in the United States. For transfers from the EU/EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), and equivalent mechanisms as applicable.

12. Children’s Privacy

Our services are not directed to individuals under 18. We do not knowingly collect personal data from minors. If you believe we have done so, contact privacy@verifinow.io.

13. Changes to This Policy

We may update this Policy periodically. We will notify Customers of material changes by email at least 30 days before the effective date and update the “Last Updated” date above.

14. Contact Information

Privacy Inquiries
Data Protection Officer
GDPR / EU Inquiries
Mailing Address
VerifiNow Inc., Attn: Privacy Team
3579 E Foothill Blvd #289
Pasadena, CA 91107