Summit Shred Swap — Biometric Data Policy
Version 0.1 — DRAFT for attorney review — September 17, 2026
1. Why this policy exists
Every Summit Shred Swap Member proves who they are with a government ID and a live selfie. Matching a selfie to an ID photo uses facial geometry, which is biometric data under Colorado law. HB24-1130 requires any business that collects biometric data — whatever its size — to publish a written biometric policy with a retention schedule and an incident protocol, to give notice and get consent before collecting it, and to delete it on a strict timeline. This is that policy. It's posted at summitshredswap.com/biometrics and is part of our Privacy Policy and Terms of Service.
2. What biometric data is involved
- What's collected: a live selfie (short video or photos) and a scan of your government ID. Stripe Identity extracts facial geometry from both and compares them.
- Who collects it: Stripe, Inc., our identity-verification provider, acting on our behalf. The images and the facial geometry go to Stripe's systems. They never reach our servers.
- What we keep: the outcome only — document verified (yes/no), selfie matched (yes/no), your legal name, your date of birth, and the ZIP code and county from your ID. None of that is biometric data.
We don't collect fingerprints, voiceprints, iris scans or any other biometric identifier, and we don't use facial recognition anywhere else in the product.
3. Why we collect it
We use the selfie match for one purpose: to confirm that the person opening the account is the person on the ID. That's what makes the rest of Summit Shred Swap work — neighbors handing expensive gear to someone they've never met, deposits and charges that land on the right person, an 18+ community, the Lender residency rule, and a non-return protocol that can name the person who didn't bring the gear back.
We don't use biometric data for marketing, profiling or tracking you in the app, and we don't use it to make automated decisions about you other than the match itself. If your match fails, a person at Stripe or Summit Shred Swap can review it.
4. Notice and consent before collection
Before the selfie step you'll see a consent screen that explains what will be collected, who collects it, why, and how long it's kept, with a link to this policy. You must affirmatively agree before the camera opens. We keep a record of when you consented and which version of this policy you saw.
Because the selfie match is genuinely necessary to provide the service — we can't safely run a peer-to-peer marketplace with unverified people — we require consent as a condition of membership. If you don't consent, you can't become a Member, and nothing is collected.
5. Retention schedule
| Data | Held by | Retention |
|---|---|---|
| Selfie images or video and the extracted facial geometry | Stripe | We request redaction as soon as the outcome is recorded — target within 24 hours of the check, and never later than the deletion triggers in Section 6 |
| ID document images | Stripe | Same as above |
| Verification outcome (verified, matched, legal name, date of birth, ZIP and county) — not biometric data | Summit Shred Swap | Until you delete your account |
| Consent record (timestamp and policy version) | Summit Shred Swap | Until you delete your account, plus [3 years] to show we had consent |
Re-verification — after an expired ID or a flagged account — starts a new session with fresh consent and the same schedule.
6. Deletion triggers
We permanently delete biometric data — or, for data Stripe holds, direct Stripe to redact it — at the earliest of:
- when the purpose for collecting it is satisfied, which for us is the moment the verification outcome is recorded;
- 24 months after your last interaction with us; or
- 45 days after we determine the data is no longer needed for the purpose we collected it for.
In practice, trigger 1 applies to nearly every check. We audit monthly for any session where redaction didn't complete and fix it.
Deletion covers every processor we've shared the data with; we confirm redaction with Stripe and keep the confirmation. If a legal hold prevents deletion, we delete as soon as the hold lifts.
7. Who can see biometric data
Nobody at Summit Shred Swap can see your selfie or ID images; our staff's access to Stripe is limited to verification outcomes. We don't sell, lease, trade or otherwise profit from biometric data, and we don't disclose it to anyone except Stripe for the verification itself, or under a valid legal order — in which case we'll tell you unless the law forbids it.
8. How we protect it
Stripe holds biometric data under its own security program — encryption in transit and at rest, access controls and independent audits. On our side, the verification outcome is stored encrypted, access is limited to staff who handle verification and claims, and every access is logged. We protect the outcome data at least as carefully as we protect any other sensitive personal data.
9. Incident protocol
If we learn that biometric data may have been accessed, disclosed or lost without authorization — at Stripe or in our own systems — we will:
- Contain — within 24 hours: pause new verifications if needed, revoke affected credentials, and confirm with Stripe what happened.
- Assess — within 72 hours: determine whose data was involved, what was exposed, and whether it's still exposed.
- Notify — tell affected Members by email and text without unreasonable delay and within the deadline Colorado law sets, saying what happened, what data was involved, what we've done and what you can do. Notify the Colorado Attorney General and any other authority the law requires.
- Fix and record — fix the cause, re-verify affected Members if their check was compromised, and keep a written record of the incident and our response.
Report a suspected incident to [security@summitshredswap.com].
10. Withdrawing consent
You can withdraw consent at any time by deleting your account (Settings, then Delete my account) or by emailing [privacy@summitshredswap.com]. Because the biometric data itself is redacted right after your check, withdrawing consent mainly means we delete your verification outcome and close your account. You can't stay a Member without a completed verification.
11. Your rights
You can ask us to confirm whether any biometric data about you still exists at Stripe, get a copy of your verification outcome and consent record, correct your outcome if the ID details were read wrong, and delete it all. Email [privacy@summitshredswap.com]; we respond within 45 days, and you can appeal a denial by replying to our decision.
12. Changes
We'll post updates here with a new date and version. If a change affects how biometric data is collected, used or kept, we'll ask for fresh consent before applying it to you.
13. Contact
Summit Shred Swap LLC · [Mailing address], Frisco, CO 80443 · [privacy@summitshredswap.com]
Version 0.1. Questions: text or email us — the number is on every booking.