What happens to your face
To prove you are a real person we have to look at your face once. This page says exactly what is collected, who touches it, how long it lives, and when it is destroyed — in plain words, because a policy nobody can read protects nobody.
The short version. A verification partner scans your ID and takes one selfie to check the faces match and that a live person is present. 5arz never receives your selfie, your ID image, or your facial geometry. We get a yes or no and a one-way hash that cannot be turned back into your document. The scan is destroyed once the match is done, and in every case within three years of your last interaction with us.
1. What counts as biometric data here
Illinois law defines a biometric identifier as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and biometric information as anything derived from one that identifies a person. The only one of these 5arz's verification involves is a scan of face geometry, produced when your selfie is compared with the photograph on your government ID.
Photographs themselves are not biometric identifiers under that definition. The measurements taken from a photograph are.
2. What is collected, and by whom
When you verify, our identity partner — Didit, or Stripe Identity when Didit is unavailable — captures inside their own secure flow:
- a photograph of your government-issued ID;
- a selfie, from which a facial geometry scan is derived;
- signals showing a live person is present rather than a photo or a screen.
That capture happens on their infrastructure, not ours. 5arz is the party that asks for the check and receives the outcome.
3. What 5arz actually stores
Three things, and nothing else:
- The result — verified or not verified.
- The partner's reference number, so a result can be traced to the check that produced it.
- A one-way hash derived from your ID number, salted with a secret only our servers hold. It cannot be reversed into your document number. Its only job is to tell us that two accounts belong to the same person, which is how we stop one person opening many accounts.
We do not hold your selfie, your ID image, or your facial geometry, and we have no way to reconstruct any of them.
4. Why we do it
To establish that you are a real, ID-verified human. That is the single thing 5arz exists to prove, and every credential we issue depends on it. The data is used for that, and to prevent one person creating many accounts.
It is never sold, leased, traded, or otherwise profited from. It is not used for advertising, and it is not used to train any model.
5. Retention and destruction schedule
This is the schedule required by 740 ILCS 14/15(a):
- The biometric identifier is destroyed when the initial purpose for collecting it — confirming you are a real, live person — has been satisfied, or within 3 years of your last interaction with 5arz, whichever occurs first.
- We require our verification partner to delete the source images and the facial geometry scan once they have returned the result to us.
- The one-way hash 5arz holds is retained while your account exists and is destroyed when you close it.
- Consent records — the fact that you agreed, when, and to which version of the notice — are kept for as long as the law allows a claim to be brought about the collection. Keeping this record is what lets us prove we asked you first. It contains no biometric data.
6. Disclosure
We disclose biometric data to exactly one category of recipient: the identity partner performing the check, named in section 2. We do so only after you have consented, which is why the consent screen names them.
We do not disclose it to anyone else unless you ask us to in writing, or a valid warrant or subpoena requires it. Businesses that use 5arz to verify their users receive a credential stating that a real, ID-verified human was verified — never the underlying biometric data.
7. Your choices
- You can decline. The consent box is unticked by default and nothing is captured until you tick it. If you would rather not, email support@5arz.com and we will find another way to verify you.
- You can withdraw consent at any time, and it is as easy to withdraw as it was to give. Email us, or use the withdrawal endpoint referenced in your account settings.
- You can ask us to delete what we hold. We will destroy the one-way hash and instruct our partner to delete anything remaining on their side.
- You can ask what we hold about you, and we will tell you.
8. How it is protected
We apply the same standard of care we use for our most sensitive data, and no less than the industry standard. In practice the strongest protection is structural: we do not hold the biometric data at all. Data we never receive cannot be leaked by us. What we do hold is a salted one-way hash that is useless to anyone who takes it.
9. Where this applies
This policy is written to Illinois BIPA because it is the strictest standard we are subject to, and then applied to everyone, everywhere. It also addresses Texas CUBI, Washington's My Health My Data Act, and — where GDPR applies — biometric data as special-category data under Article 9, for which our lawful basis is your explicit consent.
10. Changes
If this policy changes, the version number changes with it. Every consent we record stores the version and a cryptographic hash of the exact words shown at the time, so we can always show what you actually agreed to — not merely what the current page says.
11. Contact
Questions, requests, or complaints: privacy@5arz.com. Postal: 5arz, 16192 Coastal Hwy, Lewes, DE 19958.