Biometric Data Policy

Last updated: July 22, 2026

1. Why this policy exists

Identity verification on BeyondSwipe involves a one-time biometric step: a live selfie is compared against the photograph on your government-issued document to confirm you are the person that document belongs to. Biometric information is among the most sensitive categories of personal data, so we publish this separate policy setting out exactly what is collected, by whom, why, how long it is kept, and how it is destroyed.

2. What is collected, and by whom

The biometric processing is performed by Didit, acting as our service provider. Didit captures the selfie and the document image, derives facial geometry from each, and compares them.

BeyondSwipe does not collect, receive, possess, or store biometric identifiers or biometric information at any point. The images and the facial geometry derived from them are transmitted directly to Didit and are never sent to, routed through, or held on BeyondSwipe systems. Our verification is configured to return the result, a session reference, non-identifying warning codes needed to explain a refusal, and the date of birth printed on the document. We send Didit the date you entered so it can compare the two exactly, and use the extracted date transiently to confirm you are 18 or over. The extracted date is never stored or logged. No image of any kind is returned to us.

We do not use facial recognition to identify members, we do not run one-to-many searches against any database, and we do not apply biometric processing to profile photos or to any other content you upload. The only comparison performed is one-to-one, between your selfie and your own document.

3. Purpose

Biometric information is used for one purpose only: confirming that the person completing verification is the person shown on the identity document presented. It is used to prevent impersonation, stolen-identity signups, underage access, and the operation of fraudulent or duplicate accounts. It is not used for advertising, profiling, matching, ranking, training machine-learning models, or any secondary purpose.

4. Notice and consent

Before any capture takes place, we display a written notice explaining that biometric information will be collected and processed by Didit, the specific purpose, and the retention period. Verification proceeds only if you consent. You may decline, in which case you will not be able to complete verification, and an unverified account cannot connect with other members. We record the fact, version, and timestamp of consent.

5. Retention and destruction schedule

This is our permanent retention and destruction schedule for biometric data:

  • Held by BeyondSwipe: none, at any time. There is nothing for us to destroy because we never hold it.
  • Held by Didit: destroyed on completion. Immediately after a verification resolves, whether it passed or failed, our systems automatically instruct Didit to delete the verification session and remove the document images, selfie, and extracted feature data from active systems. Didit hard-deletes the soft-deleted session record under the configured retention schedule.
  • Didit backstop: the shortest window available. Our Didit account is configured to the shortest retention period the platform permits, as a backstop in case a deletion instruction does not reach them. In practice the deletion step above occurs within seconds of a verification resolving, long before any backstop applies.
  • What survives. After destruction we retain only a non-biometric record: a verification session reference, the outcome, and the date. This record contains no images and no biometric information, and is kept for the life of the account plus a limited period afterwards for fraud prevention and to enforce removals.

6. Disclosure

We do not sell, lease, trade, or otherwise profit from biometric information, and we do not disclose it to any third party. We could not do so in any case, since we never hold it. Didit processes it solely on our instructions as our service provider, subject to its own published privacy commitments. Didit stores verification data in the European Union.

7. Your rights

You may withdraw consent to the retention of biometric identifiers at any time by writing to privacy@beyondswipe.app, and we will instruct Didit to delete them. You may request deletion of your BeyondSwipe account and its verification record at any time by writing to privacy@beyondswipe.app. See our Privacy Policy for the full set of rights available to you and our response times.

8. Contact

Privacy Officer, 15748666 Canada Inc.
privacy@beyondswipe.app

See also: How verification works and Regional notices.