DoorDash · DoorDash Privacy Policy · View original document ↗

Government-Issued ID Processing for Age Verification

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for DoorDash Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When you order age-restricted products like alcohol, DoorDash may collect and process your government-issued ID and signature. The policy acknowledges this information is treated as sensitive personal data in some states and countries.

This analysis describes what DoorDash's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy identifies government-issued identification and signatures as potentially sensitive personal information and states that consent will be obtained where legally required, but does not specify in detail how consent is obtained or how long this data is retained.

Interpretive note: The policy states consent is obtained where legally required but does not specify the consent mechanism, which makes independent verification of compliance with jurisdiction-specific sensitive data consent requirements uncertain.

Consumer impact (what this means for users)

If you order alcohol or other age-restricted items, DoorDash may collect and process your government-issued ID document and signature, which the policy classifies as sensitive personal information in some jurisdictions. The policy states this data is used for fraud prevention, age verification, and legal compliance, and is not used to infer personal characteristics.

How other platforms handle this

Activision Medium

YOU MUST BE AND HEREBY AFFIRM THAT YOU ARE AN ADULT OF THE LEGAL AGE OF MAJORITY IN YOUR COUNTRY OR STATE OF RESIDENCE. If you are under the legal age of majority, your parent or legal guardian must consent to this agreement.

Replit Medium

Replit is not directed to children under the age of 13. If you are under 13 years of age, you are not permitted to use the Services. If we learn that we have collected Personal Information from a child under age 13, we will take steps to delete such information from our files as soon as possible.

Figma Medium

Our Services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without parental consent, we will take steps to delete such information. In some juris...

See all platforms with this clause type →

Monitoring

DoorDash has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Identification Documentation and Signature for Age-Restricted Products, including driver's license or other government issued identification documents, which we may process in limited circumstances such as an order for an age-restricted product (such as alcohol) or other products that require age and/or identity verification and for legal and regulatory compliance. Some of the information identified above that you choose to provide us (specifically, government issued identification and your signature, which we receive when we verify age and identity and the authenticity of a submitted government issued ID for certain orders (such as alcohol orders) to prevent fraud and demonstrate legal and regulatory compliance and precise location information, which we receive to facilitate deliveries and certain content, features and functionality within our Services), may be considered sensitive Personal Information under the laws of some jurisdictions.

— Excerpt from DoorDash's DoorDash Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Government-issued identification data is classified as sensitive personal information under the CCPA and CPRA, Colorado Privacy Act, Connecticut Data Privacy Act, and Virginia CDPA. Processing of such data may also implicate state biometric privacy laws where ID verification involves facial recognition or biometric matching. The FTC and state attorneys general have enforcement authority over misrepresentations regarding sensitive data handling. GOVERNANCE EXPOSURE: High. The collection of government-issued ID documents constitutes sensitive personal information processing in multiple jurisdictions. The policy states consent is obtained where legally required but does not specify the consent mechanism, data retention period, or the specific third-party identity verification services used. Compliance with applicable consent and data minimization requirements should be independently verified. JURISDICTION FLAGS: Illinois Biometric Information Privacy Act (BIPA) may be implicated if identity verification involves biometric data extraction from ID documents. California CPRA requires opt-in consent for sensitive data processing. Texas and Washington have analogous biometric and sensitive data frameworks. International users in Canada, Australia, and New Zealand are also covered by sensitive data provisions under their respective privacy laws. CONTRACT AND VENDOR IMPLICATIONS: Third-party identity and age verification vendors must be subject to data processing agreements limiting use to the stated purpose. Contracts should specify retention periods and require deletion of ID data after verification is complete. Vendor security certifications should be assessed given the sensitivity of the data category. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that consent mechanisms for ID document collection are jurisdiction-specific and auditable. Retention schedules for government ID data should be documented and enforced. The identity verification vendor list should be reviewed to confirm all processors are disclosed and compliant. A data protection impact assessment may be warranted for this processing activity in certain jurisdictions.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices involving the collection and handling of sensitive personal information including government-issued identification
    File a complaint →
  • State AG
    State attorneys general in California, Illinois, and other states enforce laws specifically governing sensitive personal information and biometric data processing
    File a complaint →

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
TCPA
United States Federal
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
DoorDash Privacy Policy
Entity
DoorDash
Document last updated
May 5, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-010984
Document ID
CA-D-00134
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
36c24e9e80c20d02c0f6b7f63328244e08d914ed4a197c9cb9f052fe46da8132
Analysis generated
May 12, 2026 05:01 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DoorDash
Document: DoorDash Privacy Policy
Record ID: CA-P-010984
Captured: 2026-05-12 05:01:26 UTC
SHA-256: 36c24e9e80c20d02…
URL: https://conductatlas.com/platform/doordash/doordash-privacy-policy/government-issued-id-processing-for-age-verification/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does DoorDash's Government-Issued ID Processing for Age Verification clause do?

The policy identifies government-issued identification and signatures as potentially sensitive personal information and states that consent will be obtained where legally required, but does not specify in detail how consent is obtained or how long this data is retained.

How does this clause affect you?

If you order alcohol or other age-restricted items, DoorDash may collect and process your government-issued ID document and signature, which the policy classifies as sensitive personal information in some jurisdictions. The policy states this data is used for fraud prevention, age verification, and legal compliance, and is not used to infer personal characteristics.

Is ConductAtlas affiliated with DoorDash?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DoorDash.