Incode Privacy Notice — End Users of Incode Services

Last Modified: July 22, 2026

Incode Technologies, Inc., including its subsidiaries and affiliates, (“Incode,” “we,” “our,” and “us”) respects the privacy of individuals. Please read this Privacy Notice (“Notice”) to learn more about who we are, how we collect and use your personal data, and how you can exercise your privacy rights.

1. Who We Are.

Incode is headquartered in the United States and has offices and group companies located around the world. Incode provides various age assurance, identity verification and fraud prevention services (the “Service(s)”) to businesses, companies or organizations (“Customers”). You can find out more information about Incode’s Services here.

You may print a copy of this Privacy Notice directly from your browser. If you have a disability, you may request this Privacy Notice in an alternative format by contacting us via Incode’s Privacy Inquiry Webform. Where required by applicable law, we make this Privacy Notice available in additional languages.

2. When This Notice Applies.

This Notice describes how Incode handles the personal data of individuals who use the Services (“End Users”) where Incode acts as a data controller (see Section 2.1.) and you:

  • use the Services to submit a government ID and other personal data to verify your identity or prevent fraud;
  • submit a photo or biometric information (such as a facial scan or faceprint) through the Services for age assurance, identity verification, or fraud prevention; or
  • use the Services in connection with workforce or employment-related services we provide to our Customers.

2.1. Controller vs Processor

Depending on the Service and our contractual arrangement with the Customer, Incode acts as a data controller or a data processor for the processing of your personal data. This Notice addresses Incode’s processing as a controller. Where Incode acts as a processor, the Customer’s privacy notice governs; please refer to the organization that directed you to Incode’s Services.

The sections below explain which role applies in which circumstances and what that means for you. If you are still unsure which role applies to your data, contact us using the details in the Contact Information section below.

2.1.1. When is Incode a Controller?

Incode is a data controller (or “business,” under certain U.S. laws) when we:

  • offer services directly to End Users;
  • provide the Services where Incode independently determines the purposes and means of processing your personal data;
  • use your personal data, with your consent or other lawful legal basis, to improve our products or services.

2.1.2. When is Incode a Processor?

Incode is a data processor (or “service provider,” under certain U.S. laws) when we process personal data on behalf of, and at the direction of, our Customers without independently determining the purposes or means of processing. In these cases, the referring Customer, such as a bank, employer, financial institution, or online platform, is the controller of your personal data and is responsible for determining how and why your data is processed.

Where Incode acts as a processor, this Notice does not govern the processing of your personal data. To understand how your data is handled, including applicable retention periods and how to exercise your privacy rights, please refer to the relevant Customer’s privacy notice. You may also contact that Customer directly.

If you are not an End User of Incode Services, please refer to one of our other Privacy Notices which may apply to you depending on how you interact with Incode: Customers (Businesses) or Website Visitors.

3. What Personal Data Does Incode Collect, From Where and Why?

The personal data we collect depends on the product and features you or our Customer use, your location, and applicable law. The chart below details our current practices and our practices for the 12 months preceding the Last Modified date of this Notice.

3.1. What personal data does Incode collect to provide its Services and why?

Categories of Personal Data
(The “What”)
Purposes for Collection, Use, and Disclosure
(The “Why”)

Identifiers, such as a real name, postal address, unique personal identifier, online identifier, telephone number, signature or initials, email address, account name, IP address, device identifiers, or other similar identifiers.

Financial information, such as fraudulent financial activity reported by Customers.

Demographic data / characteristics of protected classifications, including age, nationality, and gender.

Internet or other electronic network activity information, including how you interact with our Services or other analytics information.

Geolocation data.

Sensory data, including audio, electronic, visual, or similar information (e.g., photos, videos, video selfies, recordings of you and your environment, and images of your identity document).

Inferences or fraud risk pattern signals derived from successful or suspicious identity verification transactions.

To provide identity verification services, authenticate your information, and prevent fraud.

To operate and maintain our Services, provide customer service, and provide technical support.

For quality, safety, and internal research, including evaluating how our Services perform, repairing or improving the quality of our Services, tracking and responding to quality and security issues, and developing new or enhanced products and service offerings.

Sensitive personal data, including information from government-issued identification (e.g., social security number, driver’s license, state identification card, or passport number, including data encoded via NFC or the machine-readable zone) and biometric identifiers (e.g., retina or iris scans, faceprints, including facial mapping and face geometry; voiceprints; and fingerprints, including scans of digitized images).

To provide the Services, including identity verification services, authentication of your information, and prevent fraud.

3.1.1. Additional Purposes:

3.1.1.1. As authorized by applicable laws. We may also collect, use, or disclose all categories of personal data described above for purposes authorized by applicable laws, including:

  • To help prevent serious injury or to protect the personal safety of Incode personnel, users of our Services, visitors, or the public;
  • To detect, investigate, prevent, or otherwise address fraud or other security and integrity issues affecting our Services or Incode;
  • As part of a corporate transaction or proceeding such as a merger, financing, acquisition, bankruptcy, dissolution, transfer, divestiture, or sale of all or a portion of our business or assets;
  • To protect the rights or property of Incode, our affiliates, or others, including by enforcing our agreements, terms, and policies.
  • Where permitted, to create aggregated, de-identified, and dissociated data from the personal data we collect.
  • When we have a continuing legal or business reason (for example, to comply with our legal, tax, or accounting obligations or resolve disputes) permitted or required by applicable law, rule, or regulation.

3.1.1.2. Training and improving our models. Where we use biometric identifiers or other sensitive personal data to train or improve the AI/ML models that power the Services, we do so consistent with applicable law and, where required, on the basis of your consent.

3.2. Personal Data of Minors

In the course of providing certain Services, where required, Incode may process personal data of individuals under the age of 18 (“Minors”) (or the age defined under the applicable laws of the relevant jurisdiction) in accordance with the Customers instructions and applicable laws. The Customer is responsible for ensuring (i) there is a legal basis on which Incode may process a minor’s personal data and communicating any such conditions or requirements to Incode prior to the start of such processing, (ii) provision of applicable notice(s) and collection of required consent(s) for such processing (e.g., a consent from a guardian of that minor), if required, and (iii) setting the appropriate data retention instructions in the Services applicable to personal data of minors.

Incode does not “sell or share” (as those terms are defined under applicable data privacy law) personal data of Minors.

If you are a parent or guardian and believe your child’s personal data has been processed by Incode without appropriate consent or authorization, please contact us as indicated under the Contact Us section; we will promptly investigate and, where appropriate, delete the data.

3.3. Sources of Personal Data (the “where”)

We may obtain your personal data from the following sources:

  • Directly from you, such as when you use or access Incode’s age assurance, identity verification or fraud prevention Services.
  • Our Customers, such as when our Customers direct us to verify your identity or provide us with information about you in connection with their use of our Services.
  • Our service providers/vendors, such as when our vendors provide us personal data related to you in the process of providing us their services.
  • Government agencies/databases or third-party data providers, such as when we compare your personal data with records held by government entities (e.g., a State Department of Motor Vehicles or equivalent agencies) or private or public databases, directly or through Service Providers.
  • External sources, such as publicly accessible government records or databases, to validate personal details you provide when verifying your identity.

4. To Whom Does Incode Disclose Personal Data To?

We may disclose your personal data to the categories of recipients listed below, and where required by applicable law, will do so with your consent:

  • Service Providers/Vendors: These vendors help us provide the Services or perform business functions on our behalf and will only process your personal data for purposes described in this Privacy Notice. They include:
    • Hosting, technology, communication, and database providers;
    • Security and fraud prevention consultants;
    • Support and customer service vendors;
    • Credit bureaus; and
    • Identity verification and fraud detection agencies;
  • Government Agencies/Databases: We may (as required by the Customer and as legally permitted) disclose the personal data on your government-issued ID and your biometric identifiers for the purpose of verifying your identity against the official government source that issued your ID. When legally permitted and explicitly requested by a Customer, this may include comparing a user-provided image against records maintained by the Department of Motor Vehicles (DMV) or an equivalent government agency. This process returns only a verification result (e.g., “match / no match”) and does not involve cross-client data sharing.
  • Our Customers: We may disclose your personal data to the Customer on whose behalf we are providing the Services. Our Customers will use and disclose personal data in accordance with their own privacy practices and obligations. We invite you to contact or refer to the relevant Customer if you need any further information regarding the privacy practices of our Customers.
  • Business Partners: These parties collaborate with us in offering various services. They include businesses that you have a relationship with, and companies that we partner with to offer joint offerings or opportunities.
  • Government Authorities: We may disclose any personal data that we collect when required or permitted by law, such as to law enforcement agencies, courts, regulatory agencies, and others, including to comply with valid legal process.
  • Business Transfers: Your personal data may be transferred to a third party (and their agents and advisers) if we undergo a merger, acquisition, bankruptcy, financing, dissolution, transfer, divestiture, sale of all or a portion of our business or assets, or other transaction in which that third party assumes control of our business (in whole or in part).

Incode does not “sell” your personal data, “share” it for cross-context behavioral advertising, or process it for purposes of targeted advertising, as those terms are defined in appliable privacy laws.

5. Data Security

We seek to protect your personal data from unauthorized access, use, and disclosure using appropriate physical, technical, organizational, and administrative security measures based on the type of personal data and how we are processing that personal data. These measures include encryption of personal data in transit and at rest, access controls, and continuous monitoring. For certain Services, Incode offers on-device processing which allows collection and processing of biometric identifiers to occur on your device. Although we work to protect the security of your personal data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.

6. Data Retention

Since needs can vary for different data types in the context of the different services we provide or depending on whether we are the controller or processor, actual retention periods can vary.

Where we are the controllers of personal data, we retain personal data about you for as long as necessary for the purpose(s) for which it has been collected and in accordance with applicable laws and regulations. In some cases, we retain personal data for longer when we have a continuing legal or business reason (for example, to comply with our legal, tax, or accounting obligations, resolve disputes, or collect fees owed), or where it is otherwise permitted or required by applicable law, rule, or regulation.

Where we are the processors of personal data, our Customers determine their applicable data retention periods and we encourage you to review the applicable privacy notice for further information.

For information regarding our retention of biometric data, please see our Biometric Data Policy and Notice.

7. Your Rights Regarding Your Data

7.1. Marketing:

You have the right to opt out of marketing communications we send you at any time. You can stop receiving marketing communications by following the unsubscribe instructions in emails that you receive.

7.2. Privacy Rights.

Subject to applicable law, you may have certain rights over the personal data we process about you as a controller. Some rights apply only in certain circumstances or to certain types of data, and some are subject to legal exemptions. We will not discriminate against you for exercising any of the rights listed here.

The most common rights include:

  • Access (To Know and Access): to know what personal data we collected about you in the last 12 months and to obtain a copy of it.
  • Correction (Rectification): to ask us to correct inaccurate personal data we hold about you.
  • Data Portability: you may have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit it to another controller where technically feasible.
  • Deletion (Erasure): to ask us to delete your personal data. This may be limited where we are permitted or required by law to keep certain information. (If you request deletion, you may no longer be able to use Services that required age or identity verification.)
  • Restriction of Processing (Objection): to ask us to limit how we use your personal data in certain circumstances.
    • Withdrawal of Consent: where we process your personal data based on your consent, you can withdraw it at any time. Withdrawing consent does not affect processing we carried out before you withdrew, or processing we carry out on a legal basis other than consent.

Please note: Where Incode is providing the Services as a processor for the Customer, we cannot act on your privacy rights requests directly. To exercise your rights in that case, please contact the organization that asked you to complete the age assurance or identity verification process to exercise your privacy rights.

7.3. Submitting a Request:

To submit a Privacy Rights Request, you or your authorized agent may use Incode’s Privacy Inquiry Webform to make your request.

We are required by law to take reasonable steps to verify your identity prior to responding to your request by asking for information sufficient to confirm your identity, based on the information we have on file.

If using an authorized agent to submit your request, you must provide your authorized agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission when they make a request on your behalf. Where an access request is made by an authorized agent, we shall only deliver the file to the End User as a matter of privacy and security.

7.4. Appeal Process:

Requests to exercise these rights may be granted in whole, in part, or not at all, depending on the scope and nature of the request and as permitted by applicable law. Where we reject your request, we will notify you of the reasons we are unable to honor your request and provide you with instructions regarding the appeals process.

7.5. Lodging a Complaint:

You have the right to lodge a complaint about Incode’s practices with respect to your personal data with a supervisory authority, in particular, in the jurisdiction where you reside.

8. Cross-Border Transfers of Personal Data

Incode is headquartered in the United States, with service providers and infrastructure located in the United States and other countries. Your personal data may be transferred to, and processed in, countries outside of your country of residence, including the United States. These countries may have data protection laws that differ from those of your jurisdiction. Where required by applicable law, Incode ensures that cross-border transfers of personal data are carried out with adequate safeguards, including the use of contractual clauses, consent, or other legally recognized mechanisms to provide an appropriate level of protection for your personal data.

9. Additional Information for Residents in Specific Regions

The following sections contain additional information for residents of specific regions. Where any provision in these sections conflicts with any other provision of this Notice, the region-specific provision shall govern for residents of that region.

9.1. California Residents

If you are a California resident that uses the Services, the following information applies to you and supplements the information contained in this Notice. In the event of any conflict between this section and any other provision of this Notice, this section shall govern for California residents.

References to “personal data” in this section are equivalent to “personal information” as defined by California law.

Please note that “Shine the Light” rights and “CCPA” rights are granted by different laws and must be exercised separately.

9.1.1. The California Consumer Privacy Act (“CCPA”)

Your Privacy Rights. Under the CCPA, California residents have the following additional rights besides those listed above:

  • Right to Limit Use of Sensitive Personal Information: We use sensitive personal information, such as biometric and government-ID information, only to perform the identity verification and fraud prevention services reasonably expected by an average consumer who has requested such Services and for other purposes permitted under the CCPA, and not for purposes that would require offering you a right to limit beyond those permitted uses.
  • Opt-Out of Sale and Certain Sharing Practices: We do not sell, share, or process for targeted advertising personal data collected from End Users.

9.1.2. California Shine the Light Law

California law permits customers in California to request certain details about how their personal data is shared with third parties, and in some cases affiliates, if personal data is shared for those third parties’ or affiliates’ own direct marketing purposes. We do not share personal data with third parties or affiliates for those third parties’ or affiliates’ own direct marketing purposes, therefore such requests are not applicable.

9.2. European Residents (EEA, UK, and Switzerland — GDPR)

If you are located in the European Economic Area (“EEA”), United Kingdom (“UK”), or Switzerland you may have additional rights under the EU General Data Protection Regulation (the “GDPR”), the UK GDPR, and other European data protection laws with respect to your personal data, as outlined below. If there are any conflicts between this section and any other provision of this Privacy Notice, this section shall govern for residents of the EEA, the UK, and Switzerland.

The controller of your personal data (for processing purposes described in this Notice, i.e., excluding processing performed solely on behalf of our Customers as a processor) is Incode Technologies, Inc. See the Contact Information section below contact details.

9.2.1. Legal Basis for Processing Personal Data

We will only process your personal data if we have a lawful basis for doing so under Article 6 of the GDPR. The legal basis we rely on depends on the specific processing activity:

  • Contractual Necessity (Article 6(1)(b)): We process your personal data as a matter of “contractual necessity,” meaning that we need to process the data to perform a contract with you, such as to provide you with the Services through our Customers’ applications and/or websites.
  • Legitimate Interests (Article 6(1)(f)): We may also process your personal data where it is necessary for our legitimate interests or the interests of a third party, provided those interests are not overridden by rights. Examples include providing, customizing, and improving the Services; preventing fraud; corresponding with you; promoting the Services; and maintaining the security of the Services. You have the right to object to processing based on legitimate interests at any time.
  • Consent (Article 6(1)(a) and, for special categories of data, Article 9(2)(a)): In some cases, we process personal data, including biometric data constituting special category data, based on your explicit consent. Where we rely on consent, it will be expressly indicated to you at the point of collection. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Legal Obligation (Article 6(1)(c)): We may also need to process personal data where necessary to comply with legal obligations, to protect the vital interests of you or other individuals, or perform a task carried out in the public interest.

Where we process biometric identifiers (such as faceprints or facial geometry) for the purpose of uniquely identifying you, this constitutes special category data under Article 9 of the GDPR. We process such data only where we have obtained your explicit consent (Article 9(2)(a)), or where processing is necessary for reasons of substantial public interest on the basis of applicable law (Article 9(2)(g)), as applicable.

Provision of your personal data is a requirement necessary to use the Services (e.g., identity verification requires submission of your identity document and facial image). If you do not provide the required data, we will be unable to perform the identity verification or age assurance service.

9.2.2. European Data Subject Rights

European residents have rights of access, portability, rectification, erasure, restriction of processing, objection, and withdrawal of consent, as described in Section 7.2. To submit a request, please follow the process addressed in Section 7.3.

  • Lodging a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with applicable data protection laws. For EEA residents, this may include the supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement. A list of supervisory authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en. UK residents may contact the UK Information Commissioner’s Office, and Swiss residents may contact the Swiss Federal Data Protection and Information Commissioner.

9.2.3. Transfers of personal data

Incode is a United States company with service providers located in the United States and other countries. This means that your personal data may be transferred to, and processed in countries outside of the EEA (“Third Countries”). These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective).

We apply the following safeguards to ensure the protection of your personal data is not undermined:

  • For recipients in Third Countries with an adequate level of protection (you can find the current list of adequate Third Countries here), we rely on the EU Commission’s adequacy decisions under Art. 45 GDPR.
  • For recipients in Third Countries without an adequate level of protection, we usually rely on standard contractual clauses (you can find the text of the standard contractual clauses here) under Art. 46 GDPR.

For recipients in Third Countries without an adequate level of protection and in the absence of standard contractual clauses, we rely on derogations under Art. 49 GDPR, for example, if

  • you have given your explicit consent,
  • it is necessary for the conclusion or performance of a contract with you or in your interests, or
  • it is necessary to establish, exercise, or defend legal claims.

For more details about our Third Country transfers or copies of these safeguards please reach out to us via the contact details below in Section 10.

9.3. Australian Residents

If you reside in Australia or are using our services or interacting with Incode in Australia, the following applies to you. This section supplements, supersedes, and extends the scope of this Privacy Notice generally. The remaining sections of this Notice, other than those expressly limited to foreign jurisdictions or inconsistent with this section, also apply to you.

9.3.1. Controller vs. Processor Under Australian Law

Some privacy regimes distinguish how we may collect, use, and disclose your personal data depending on whether we are classified as a “data processor” or “data controller.” That distinction is not relevant to you to the extent Australian privacy law applies and we have obligations to you with respect to the personal data we hold about you, regardless of the designation.

9.3.1. Disclosure of personal data outside of Australia

See Section 8.

9.3.2. Your Rights Under Australian Privacy Law

You are entitled to access the personal data we hold about you and may request that we correct any errors. If you would like to access or correct your personal data, please follow the process described in Section 7.3 and/or contact us in accordance with Section 10.

We will take reasonable steps to allow you to access your personal data unless reasonable circumstances would prohibit us from doing so, and we will correct personal data that is inaccurate, out of date, incomplete, irrelevant, or misleading. If you are concerned that we may have breached the Australian Privacy Principles, please contact us and we will undertake a reasonable and expeditious assessment, completed as soon as practicable and in any event within 30 days. If you are unsatisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.

9.4. Residents of Brazil, Colombia, Mexico and other Latin American Countries

If you reside in Latin America, including Brazil, Colombia, Mexico, and other Latin American countries, you may have additional rights under applicable privacy laws. These rights may include the ability to access, correct, cancel, delete, or object to the processing of your personal data (sometimes known as “ARCO” rights), as further described in Section 7.2.

10. Changes to this Privacy Notice

We may update this Privacy Notice from time to time, and, in some cases, we may provide you with additional notice at our discretion. You can see when this Privacy Notice was last updated by checking the “Last Modified” date displayed at the top of this Privacy Notice.

11. Contact Information

If you have any questions or comments about this Privacy Notice, the ways in which we collect and use your personal data, or your choices and rights, please do not hesitate to contact us at:

  • Privacy Inquiries: Webform
  • Mail: Incode Technologies, Inc., Attention: Privacy Office, 101 Mission Street, Suite 900, San Francisco, CA 94105