Checkout.com · Checkout.com Privacy · View original document ↗

Biometric Data Collection and Retention

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Checkout.com changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Checkout.com recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Checkout.com Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice authorizes collection of facial images and voice recordings from which biometric identifiers (faceprints, voiceprints, minutiae templates) are extracted for identity verification, with that biometric data shared with Snowflake Computing and Amazon Web Services and retained for up to 365 days before deletion.

This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are operationally significant parameters for compliance with GDPR, UK GDPR, and US state-level biometric privacy statutes that impose consent, disclosure, and retention requirements.

Interpretive note: The phrase 'or if our collection of biometric information is otherwise permitted by law' reserves a non-consent legal basis that is not further specified, and the adequacy of the stated consent mechanism under US state biometric laws (BIPA, Texas CUBI) requires jurisdiction-specific legal evaluation.

Recent Activity

This document changed recently

Medium Jun 19, 2026

The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.

View change record →

Consumer impact (what this means for users)

This provision establishes that Merchant Customers who use Checkout's identity verification services may have facial images, voiceprints, and derived biometric templates collected, shared with Snowflake Computing and Amazon Web Services, and retained for up to 365 days, with processing stated to require explicit consent. The agreement also states that biometric collection may proceed where otherwise permitted by law, independent of consent.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email dpo@checkout.com to submit a biometric data deletion request, identifying yourself and specifying the biometric data you wish deleted. The notice states data is deleted no later than 365 days after collection.

Cross-platform context

See how other platforms handle Biometric Data Collection and Retention and similar clauses.

Compare across platforms →

Monitoring

Checkout.com has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you consent to our collection of biometric information or if our collection of biometric information is otherwise permitted by law, you agree that we may collect your imagery of the face, and voice recordings, from which an identifier template such as a faceprint, a minutiae template, or a voiceprint, can be extracted in order to verify your identity using Checkout's verification services. Your biometric information may be shared with our third-party cloud providers Snowflake Computing and Amazon Web Services. We will delete your biometric information no later than 365 days after the date you provide it.

Excerpt from Checkout.com's Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 9 (special category data) and UK GDPR Article 9, which require explicit consent or another Article 9(2) basis for processing biometric data. In the US, Illinois BIPA, Texas CUBI, and Washington My Health MY Data Act impose specific written consent, disclosure, prohibition on sale, and retention/destruction requirements for biometric identifiers and templates; the notice does not explicitly address these frameworks by name. The FTC may also examine biometric data practices under Section 5 of the FTC Act. The named processors (Snowflake Computing and Amazon Web Services) as recipients of biometric data must be evaluated under GDPR Article 28 processor agreement requirements. 2. GOVERNANCE EXPOSURE: High. The provision authorizes sharing of biometric identifiers with two named third-party cloud providers and retains data for up to 365 days. The clause also contains the phrase "or if our collection of biometric information is otherwise permitted by law," which reserves a non-consent legal basis that is not further specified in the document, creating ambiguity about the conditions under which biometric processing may proceed without explicit consent. 3. JURISDICTION FLAGS: Illinois BIPA creates heightened exposure as it provides a private right of action for violations of its biometric data consent and retention requirements, and the 365-day retention period would need to be evaluated against BIPA's requirement to destroy biometric data when the initial purpose is fulfilled or within three years, whichever is earlier. Texas and Washington state laws impose similar obligations. EU and UK data subjects benefit from GDPR Article 9 explicit consent requirements and the right to withdraw consent. California CPRA classifies biometric data as sensitive personal information subject to additional restrictions. 4. CONTRACT AND VENDOR IMPLICATIONS: The naming of Snowflake Computing and Amazon Web Services as biometric data recipients creates a procurement due diligence trigger: data processing agreements with these vendors should be confirmed to include the required GDPR Article 28 terms, biometric-specific handling obligations, and deletion obligations aligned with the 365-day commitment in this notice. Organizations using Checkout as a payment processor should also assess whether their own privacy notices adequately disclose downstream biometric processing by Checkout. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should verify: (a) whether the consent mechanism for biometric collection satisfies the written informed consent requirements of applicable state biometric laws; (b) whether data processing agreements with Snowflake and AWS are current and include biometric-specific handling terms; (c) whether the 365-day retention period is documented with operational justification supporting data minimization compliance; and (d) whether the non-consent legal basis reserved by the phrase "otherwise permitted by law" is documented with a specific legal basis for each jurisdiction in which it may be invoked.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has issued guidance and enforcement actions regarding biometric data collection and consumer data practices under Section 5 of the FTC Act.
    File a complaint →
  • State AG
    State attorneys general in Illinois, Texas, Washington, and California have enforcement authority over state-level biometric and sensitive data privacy statutes implicated by this provision.
    File a complaint →

Provision details

Document information
Document
Checkout.com Privacy
Entity
Checkout.com
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016110
Document ID
CA-D-00663
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
aabf92a3ffd7ad34135ff9f030ee34d8f733b33feed3b830c2380fe5554a223b
Analysis generated
July 9, 2026 09:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Checkout.com
Document: Checkout.com Privacy
Record ID: CA-P-016110
Captured: 2026-07-09 09:37:20 UTC
SHA-256: aabf92a3ffd7ad34…
URL: https://conductatlas.com/platform/checkoutcom/checkoutcom-privacy/provision/CA-P-016110/biometric-data-collection-and-retention/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Checkout.com's Biometric Data Collection and Retention clause do?

This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are operationally significant parameters for compliance with GDPR, UK GDPR, and US state-level biometric privacy statutes that impose consent, disclosure, and retention requirements.

How does this clause affect you?

This provision establishes that Merchant Customers who use Checkout's identity verification services may have facial images, voiceprints, and derived biometric templates collected, shared with Snowflake Computing and Amazon Web Services, and retained for up to 365 days, with processing stated to require explicit consent. The agreement also states that biometric collection may proceed where otherwise permitted by law, independent of …

Is ConductAtlas affiliated with Checkout.com?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.