Biometric Data, Privacy & App Permissions Policy
Last updated: [7/20/2026]
1. Scope of This Policy
This policy explains how MadeCentz ("Company") collects, uses, and stores biometric identifiers and biometric information as part of identity verification, and what device permissions the Platform requests. This policy supplements, and does not replace, the general Terms of Service. Where required by law, the Company will obtain your separate, explicit, written consent before collecting biometric data, in addition to your acceptance of this policy.
2. What Biometric Data Is Collected
To confirm a Job, Earn Users must complete identity verification. This is performed by Stripe Identity, a third-party identity verification service, not directly by the Company. As part of that process, Stripe collects a photo of your government-issued ID and a live selfie or short video, from which facial geometry (a biometric identifier) is derived to confirm the ID belongs to you.
- The Company does not itself capture, view, or independently store the raw biometric scan. The Company receives a verification result (verified / not verified, and limited identity attributes) from Stripe Identity, governed by Stripe's own privacy policy and biometric practices, which you will be separately prompted to review and accept before verification begins.
- If the Company's own systems retain any biometric identifier or derived template outside of the Stripe Identity flow, that data is used solely for identity verification and fraud prevention, is encrypted at rest, and is not sold, leased, or disclosed for any commercial purpose unrelated to Platform safety and compliance.
2.1 Verification Requirements, Failed Attempts, and Security Warnings
- Accepted identification: you must submit a current, unexpired, government-issued photo ID accepted by Stripe Identity's verification process (typically a driver's license, state ID, or passport). Expired IDs, non-government IDs, photocopies, screenshots, or a photo of an ID displayed on another screen are not accepted. [Confirm the current list of accepted document types with Stripe before publishing, since accepted types may change over time.]
- Declined vs. failed verification: if you decline to complete identity verification, you will not be permitted to confirm or perform Jobs, as described in the Terms of Service. If you attempt verification and it is unsuccessful, you will be given an opportunity to retry; after multiple unsuccessful attempts, verification will be treated as failed for that session, and you will not be able to confirm or perform new Jobs. A failed verification does not, by itself, restrict your ability to access your account or withdraw a balance already earned from previously completed Jobs — though the Company may separately place a hold on an account under the Terms of Service if fraud is suspected.
- Signing up on a personal device (phone, laptop, or tablet not shared with or used by others) is strongly recommended over a shared or public device, such as a library or school computer. Signing up on a device associated with many other accounts may be flagged as higher-risk by the Payment Processor's fraud detection and could delay or block verification.
- Security warning: the Company and Stripe will never ask you to submit your ID, selfie, or account credentials outside of the official verification flow within the Platform. Do not provide this information to anyone who contacts you claiming to be from the Company or Stripe by email, text, or phone, and do not respond to such requests. Report any suspected impersonation attempt to the Company immediately.
3. Purpose of Collection
- Confirming an Earn User's identity before they may accept and perform a Job.
- Fraud prevention and account security.
- Complying with the Company's obligations to its Payment Processor and applicable financial regulations.
- Determining the U.S. state associated with an Earn User's verified identity, solely to apply the correct state minimum-age and other state-specific eligibility rules described in the Terms of Service.
3.1 Address Data Minimization
The Payment Processor's identity verification service extracts a full parsed address (street, city, state, postal code) from a submitted government ID. The Company does not request, store, or retain the street address, city, or postal code portions of this data. The Company retrieves and stores only the two-letter state code, captured once at the time identity verification completes, for the sole purpose described above. The remainder of the extracted address data stays with the Payment Processor and is governed by its own retention policy, not the Company's.
3.2 Self-Reported Profile Information (Phone, Email, Date of Birth, State)
Before an Earn User can express interest in a Job for the first time, the Company collects and stores a verified phone number, a verified email address, a self-reported date of birth, and a self-reported state of residency. This information is not biometric data. It is used for two purposes: (a) enabling Create Users and the Company to contact the Earn User about a Job, and (b) as a preliminary eligibility screen to apply the minimum-age and state-specific rules described in the Terms of Service before the Earn User proceeds further.
This self-reported information is a preliminary check only. It is not the Company's authoritative source for age or state eligibility. Once the Earn User completes identity verification, the age and state derived from the Earn User's government ID control for all eligibility determinations under the Terms of Service, and the Company reconciles the self-reported date of birth and state against the verified values. A material mismatch between the self-reported information and the verified information may be treated as a misrepresentation under the Terms of Service.
4. Consent
By proceeding through the identity verification flow, you affirmatively consent to the collection and processing of the biometric identifiers described above for the purposes stated in Section 3. You may decline to complete identity verification, but you will not be permitted to confirm or perform Jobs as an Earn User if you do.
5. Retention and Destruction
Identity verification is performed by Stripe Identity, and retention of the underlying data is governed by Stripe's data-handling terms and by the Company's agreement with Stripe. Under Stripe's current practices:
- Biometric identifiers (the facial-geometry data derived from your selfie and ID to confirm they match) are removed from Stripe's systems within one year. Stripe retains them during that period to detect fraud across identity documents over time. You may opt out of Stripe's use of your biometric information at any time by contacting [email protected].
- Non-biometric identity data (images of your ID and selfie, and extracted data such as name, date of birth, and ID number) is retained by default for three years, and may be deleted sooner on request.
The Company itself does not independently store the raw biometric scan (see Section 2). Where the Company retains any derived identity data, it does so only as long as necessary for the purposes described in this policy, and in no event longer than the shorter of: (a) the period Stripe retains the corresponding data, or (b) the retention period required by applicable law. Upon expiration of the applicable period, biometric data is permanently destroyed by Stripe or the Company, subject to any legal hold or record-keeping obligation (for example, anti-money-laundering requirements) that prevents earlier deletion.
To request deletion of, or to revoke consent for, data held by Stripe, contact [email protected]. To request deletion of data the Company holds, contact [PRIVACY EMAIL].
6. State and Local Biometric Privacy Laws
Certain states and cities impose specific requirements on the collection of biometric data. This section is a summary, not a substitute for jurisdiction-by-jurisdiction legal review before launch.
- Illinois (Biometric Information Privacy Act, "BIPA"): requires written notice, written consent, a publicly available retention/destruction schedule, and prohibits profiting from biometric data. BIPA includes a private right of action with statutory damages ($1,000–$5,000 per violation) — this is the single highest-risk biometric statute in the country for a platform of this kind, and legal review specific to BIPA is strongly recommended before onboarding any Illinois resident.
- Texas (Capture or Use of Biometric Identifier Act, "CUBIA"): similar consent and destruction requirements, enforced by the Texas Attorney General (no private right of action, but civil penalties can be significant).
- Washington (H.B. 1493): requires notice and consent before enrolling biometric identifiers for a commercial purpose.
- California: biometric information is classified as "sensitive personal information" under the CCPA/CPRA, giving California residents the right to limit its use and disclosure, and requiring disclosure in a CCPA-compliant privacy notice. California does not currently have a BIPA-style private right of action for biometric data specifically, but general CCPA remedies may apply.
- New York City (Local Law 3743 / biometric identifier ordinances) and Portland, OR also impose commercial biometric notice requirements that may apply depending on where Users are located.
Because identity verification is outsourced to Stripe Identity, part of this compliance burden is shared with Stripe under its own terms — but the Company remains independently responsible for its own notice and consent obligations to Users.
7. App Permissions
The Platform's mobile application may request the following device permissions. You may decline any permission, though declining certain permissions may limit functionality as noted.
- Camera: required to capture your government ID and selfie during identity verification, and optionally to upload photos of completed Jobs or profile photos.
- Location: used to show nearby Jobs to Earn Users and to allow Create Users to set a Job location. Precise location may be requested only while the app is in use.
- Photo library: used to upload profile photos, certification documents, or Job-completion photos.
- Push notifications: used to alert you to new Job matches, messages, and payment status. May be disabled in device settings.
8. Data Sharing with the Payment Processor
Information you submit for identity verification, W-9 tax reporting, and ACH bank account setup is transmitted directly to Stripe and its identity/tax subprocessors. The Company receives only the minimum information necessary to operate the Platform (such as verification status, payout status, and tax-form completion status) and does not store full bank account numbers or unredacted Social Security/Tax ID numbers where Stripe's hosted flow is used to collect them directly.
9. Your Rights
Depending on your state of residence, you may have rights to access, correct, delete, or limit the use of your personal and biometric information, and to opt out of certain data sharing. Requests can be submitted to [PRIVACY CONTACT EMAIL]. The Company will respond within the time period required by applicable law.
10. Contact
MadeCentz LLC — 5431 BOXWOOD CT SE. KENTWOOD, MI 49512 — [email protected]