Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement authorizes BAM to collect name, address, phone number, device IP, email, date of birth, taxpayer identification number, Social Security number, government ID scans, occupation and income data, expected trading amounts, source of wealth information, bank account details, and biometric information, with a stated commitment to request consent before collecting biometric data.
This analysis describes what Binance.US's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses a broad set of personal data categories collected for identity verification and AML compliance purposes, including biometric information and financial account details. The stated consent mechanism for biometric data collection requires evaluation against applicable state biometric privacy statutes that impose specific written consent, retention schedule, and destruction requirements.
The updated terms introduce automatic enrollment in Soft-Staking for eligible tokens held in user accounts, meaning assets will be staked on Binance.US's behalf with third-party providers unless users opt out before the policy takes effect. Previously, the terms stated staking was optional and required explicit designation. The revised language also establishes that starting July 1, 2026, users will receive at least 14 days' notice before material changes to fee schedules, terms, or account policies take effect. Users can avoid automatic staking by opting out before July 1, 2026, or by withdrawing or designating specific tokens as ineligible for Soft-Staking.
View change record →Under this clause, users are required to provide extensive personal, financial, and potentially biometric information as a condition of accessing the platform's services. BAM states it will request separate consent before collecting biometric information, but the terms do not specify the form of that consent or retention and deletion timelines.
Cross-platform context
See how other platforms handle Biometric and Extensive Personal Data Collection for Identity Verification and similar clauses.
Compare across platforms →Monitoring
Binance.US has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"The information we request may include certain personal information, including, but not limited to, your name, address, telephone number, device IP address, email address, date of birth, taxpayer identification number, social security number or government identification number, scans of government-issued identity documents, occupation and income information, expected trading amounts/sources of wealth, and when applicable, bank account information (such as the name of the bank, the account type, routing number, and account number) and in some cases (where permitted by law), special categories of personal data, such as your biometric information. BAM will request your consent before collecting any biometric information from you.Excerpt from Binance.US's Terms of Use
1. REGULATORY LANDSCAPE: Biometric data collection engages the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington My Health MY Data Act, each of which imposes specific written consent, retention schedule disclosure, and data destruction requirements. Collection of Social Security numbers, government IDs, and financial account information engages Gramm-Leach-Bliley Act safeguards requirements and FinCEN Customer Identification Program rules under the Bank Secrecy Act. CCPA and CPRA apply to California residents with respect to the sensitive personal information categories disclosed here. 2. GOVERNANCE EXPOSURE: High. The breadth of data categories collected, including biometric information, Social Security numbers, and source of wealth information, creates significant regulatory exposure under multiple state biometric and data privacy statutes. The terms' statement that biometric consent will be requested does not specify whether it meets BIPA's requirement for a written release prior to collection or whether a retention and destruction schedule is provided to users. 3. JURISDICTION FLAGS: Illinois users are subject to BIPA's private right of action for biometric data violations, which includes statutory damages. Texas CUBI and Washington statute create additional compliance obligations. California CPRA designates biometric data, Social Security numbers, and financial account information as sensitive personal information subject to heightened disclosure and opt-out rights. New York SHIELD Act imposes data security requirements for this category of information. 4. CONTRACT AND VENDOR IMPLICATIONS: The terms authorize BAM to disclose personal data to identity verification, credit reference, fraud prevention, and financial crime agencies. Vendor agreements with these third parties should be assessed for data processing obligations consistent with applicable privacy frameworks. The terms also authorize disclosure of 2FA data to a third-party authentication provider. 5. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the biometric consent mechanism satisfies BIPA's written release requirement and that a publicly available retention and destruction schedule exists. Data mapping should include all categories enumerated in this provision. CCPA sensitive personal information disclosures and opt-out mechanisms should be audited for completeness. The terms' authorization to collect behavioral information and VPN/ISP IP address data should be assessed for consistency with applicable tracking and surveillance disclosure requirements.
This provision discloses a broad set of personal data categories collected for identity verification and AML compliance purposes, including biometric information and financial account details. The stated consent mechanism for biometric data collection requires evaluation against applicable state biometric privacy statutes that impose specific written consent, retention schedule, and destruction requirements.
Under this clause, users are required to provide extensive personal, financial, and potentially biometric information as a condition of accessing the platform's services. BAM states it will request separate consent before collecting biometric information, but the terms do not specify the form of that consent or retention and deletion timelines.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Binance.US.