Provision record
GOAT · GOAT Privacy Policy · View original document ↗

Biometric Identifier Collection via Facial Recognition (Persona)

High severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track GOAT and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

GOAT uses a third-party provider, Persona, to perform identity verification by applying facial recognition technology to a selfie and government ID document, generating a biometric identifier that Persona retains until GOAT instructs its destruction; GOAT states it does not receive the biometric identifier itself but does receive the selfie image and extracted ID document data.

This analysis describes what GOAT's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that biometric identifiers derived from facial geometry are generated and held by a third-party processor on GOAT's behalf, which implicates state biometric privacy statutes, particularly Illinois BIPA, that impose specific notice, written consent, retention schedule, and destruction obligations on entities that collect or contract for the collection of biometric identifiers. The provision establishes GOAT's contractual control over the destruction timeline, which may affect how regulatory obligations are allocated between GOAT and Persona.

Interpretive note: Whether GOAT's contractual arrangement with Persona (in which Persona holds but GOAT does not receive the biometric identifier) satisfies BIPA's obligations for entities that 'collect' or 'obtain' biometric data is legally uncertain and may vary by jurisdiction and enforcement interpretation.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

This provision establishes that users who undergo identity verification on GOAT's platform have a biometric identifier generated from their facial image by Persona, a third-party provider, and that this identifier is retained by Persona until GOAT instructs deletion. The agreement states that GOAT does not use, disclose, or retain biometric information for any other commercial purpose beyond the identity verification process described.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Send an email to privacy@goat.com requesting deletion of your personal information, including any identity verification data. Include your name and the email address associated with your account.

Cross-platform context

See how other platforms handle Biometric Identifier Collection via Facial Recognition (Persona) and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Persona may use a combination of machine-learning tools and optical scans to verify your identity document and may use facial recognition technology to produce a unique biometric identifier based on facial geometry that can be used to compare your selfie to the image on the identity document you provide to determine the likelihood that the images are a "match." We do not receive the biometric identifier generated from the images. It is generated and held by Persona until we inform them that the biometric identifier is no longer needed for the purposes described in this paragraph and must be destroyed.

Excerpt from GOAT's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
GOAT Privacy Policy
Entity
GOAT
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
July 9, 2026
Record ID
CA-P-016261
Document ID
CA-D-00736
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0787144e6e94c8f94e25d111a32de5d33f857ac588bc8c3d3e954bccbcd71826
Analysis generated
May 10, 2026 04:33 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GOAT
Document: GOAT Privacy Policy
Record ID: CA-P-016261
Captured: 2026-05-10 04:33:03 UTC
SHA-256: 0787144e6e94c8f9…
URL: https://conductatlas.com/platform/goat/goat-privacy-policy/provision/CA-P-016261/biometric-identifier-collection-via-facial-recognition-persona/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does GOAT's Biometric Identifier Collection via Facial Recognition (Persona) clause do?

This provision discloses that biometric identifiers derived from facial geometry are generated and held by a third-party processor on GOAT's behalf, which implicates state biometric privacy statutes, particularly Illinois BIPA, that impose specific notice, written consent, retention schedule, and destruction obligations on entities that collect or contract for the collection of biometric identifiers. The provision establishes GOAT's contractual control over …

How does this clause affect you?

This provision establishes that users who undergo identity verification on GOAT's platform have a biometric identifier generated from their facial image by Persona, a third-party provider, and that this identifier is retained by Persona until GOAT instructs deletion. The agreement states that GOAT does not use, disclose, or retain biometric information for any other commercial purpose beyond the identity verification …

Is ConductAtlas affiliated with GOAT?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GOAT.