Skip to main content

Biometric Data Policy

Last updated: April 2026 | Effective immediately

This Biometric Data Policy describes how VeriRent (operated by Numen) collects, uses, stores, retains, and destroys biometric identifiers and biometric information ("biometric data") in connection with our tenant screening service. This policy is made publicly available as required by applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, the Washington Biometric Identifier statute, and similar state laws.

1. Definitions

  • Biometric identifier: Facial geometry — the mathematical representation of the spatial relationships between facial features (e.g., distance between eyes, nose shape, jawline contour) derived from photographs and live video.
  • Biometric information: Any information derived from biometric identifiers used to identify an individual, including facial similarity scores and liveness detection results.

2. What We Collect

During the tenant screening process, we collect:

  • A live selfie photograph captured during identity verification
  • A photograph of a government-issued identity document (e.g., driver's license, passport)
  • Facial geometry data extracted from both images by our identity verification provider
  • Similarity scores from comparing the selfie to the ID photograph

3. Purpose of Collection and Use

We collect and use biometric data for the following specific purposes, and no others:

  • Identity verification (1:1 comparison): Confirming that the person completing the screening application is the same person depicted on the government-issued ID they submitted. This is done by comparing the live selfie to the ID photograph.
  • Liveness detection: Confirming that the selfie is from a live person (not a photograph of a photograph, deepfake, or other spoofing attempt).

We do NOT use biometric data for: advertising, profiling, AI model training, sale to third parties, law enforcement cooperation, or any purpose other than those listed above.

4. Consent

Before collecting biometric data, we obtain your informed, written consent through the Screening Authorization Disclosure presented during the tenant application process. This consent specifically discloses:

  • That biometric data (facial geometry) will be collected
  • The specific purpose (identity verification)
  • The retention period (30 days from screening completion)
  • A link to this Biometric Data Policy

You may withdraw consent at any time by emailing privacy@verirent.io. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

5. Third-Party Processor

Biometric data processing (facial geometry extraction, comparison, and liveness detection) is performed by our identity verification provider, a specialist third party. The provider operates as a data processor under our instructions and is contractually bound to:

  • Process biometric data only for the purposes we specify
  • Delete biometric data upon our instruction or within 30 days of screening completion
  • Implement appropriate technical and organizational security measures
  • Not use biometric data for its own purposes or share it with other parties

VeriRent stores the selfie image, ID document image, and numerical similarity and liveness scores on its own servers; all are deleted on the 30-day retention schedule below. Facial geometry data used during verification is processed by the identity verification provider and is also deleted on the same 30-day schedule.

6. Retention Schedule

Data TypeRetention PeriodStored By
Selfie image30 days from screening completionVeriRent + identity provider
ID document image30 days from screening completionVeriRent + identity provider
Similarity scores30 days from screening completionVeriRent + identity provider
Liveness detection result30 days from screening completionVeriRent + identity provider

All biometric data — including selfie images, ID document images, facial geometry, similarity scores, and liveness detection results — is permanently deleted within 30 days of screening completion, both from VeriRent's systems and from the identity verification provider's systems.

7. Destruction Procedures

When biometric data reaches the end of its retention period, or when the initial purpose for collection has been satisfied (whichever comes first), it is permanently destroyed as follows:

  • VeriRent systems: Selfie images, ID document images, similarity scores, and liveness detection results are deleted from storage and associated database records are nullified. Deletion is automated via a scheduled process that runs daily and is recorded in an append-only deletion log for audit purposes.
  • Identity provider systems: Facial geometry data, raw images, and session data held by our identity verification provider are deleted under the provider's data retention schedule and our data processing agreement, on the same 30-day retention period.
  • Backups: Biometric data in backups is overwritten as backup rotation cycles complete (maximum 30 additional days).

Early destruction is available on request. Email privacy@verirent.io or use our data deletion request form.

8. Security Measures

  • All biometric data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access to biometric data is restricted to automated processing systems — no VeriRent employee has direct access to facial geometry data
  • Biometric processing occurs in ISO 27001-certified data centers

9. Your Rights

You have the right to:

  • Refuse biometric collection: You may decline identity verification. Note that this will prevent completion of the screening process.
  • Withdraw consent: Email privacy@verirent.io at any time. We will destroy your biometric data within 7 business days.
  • Request information: Ask whether we possess your biometric data and for what purpose.
  • Request deletion: Request immediate destruction of your biometric data via our deletion request form or by emailing privacy@verirent.io.

10. Contact

Privacy inquiries: privacy@verirent.io

Support: support@verirent.io

Numen (operator of VeriRent) is the data controller responsible for the collection and use of your biometric data as described in this policy.