Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that the company or its service providers may collect and use biometric information for the purpose of identity verification prior to service access.
This analysis describes what Hims & Hers's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes collection of biometric information, a category subject to distinct state biometric privacy statutes including the Illinois Biometric Information Privacy Act, which impose specific consent, retention, and destruction obligations that may apply depending on user location.
Interpretive note: The biometric modality used, retention schedule, and destruction practices are not specified in the policy, and compliance with state biometric statutes including BIPA depends on implementation details not disclosed in this document.
The agreement authorizes collection and use of biometric information by the company or its service providers for identity verification purposes. State biometric privacy laws including BIPA in Illinois and comparable statutes in Texas and Washington may impose written consent, retention schedule, and destruction requirements for this data collection.
Cross-platform context
See how other platforms handle Biometric Information Collection for Identity Verification and similar clauses.
Compare across platforms →Monitoring
Hims & Hers has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Biometric information. We or our service providers may use biometric information to verify your identity prior to your use of the Service.Excerpt from Hims & Hers's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly engages the Illinois Biometric Information Privacy Act (BIPA), which requires written consent before collecting biometric identifiers and imposes specific retention and destruction obligations. The Texas Capture or Use of Biometric Identifier Act and Washington's biometric privacy law impose similar requirements. The FTC and relevant state attorneys general are enforcement authorities. CCPA and CPRA classify biometric information as sensitive personal information subject to additional protections and opt-out rights. 2. GOVERNANCE EXPOSURE: High. BIPA and similar state biometric statutes impose per-violation statutory damages and have been the basis of significant class action litigation. The policy's relatively brief description of biometric collection for identity verification does not specify the biometric modality used (facial recognition, fingerprint, voice), the retention period, or the destruction schedule, which are elements required by BIPA and similar statutes for compliant collection. 3. JURISDICTION FLAGS: Illinois BIPA creates heightened exposure due to its private right of action and statutory damages structure. Texas and Washington biometric laws impose similar substantive requirements. California CPRA requires disclosure of sensitive personal information including biometric data use and provides opt-out rights. Any biometric data collection from Illinois residents requires advance written consent and a publicly available retention and destruction policy under BIPA. 4. CONTRACT AND VENDOR IMPLICATIONS: Service provider agreements with identity verification vendors who conduct biometric collection on the company's behalf should include contractual commitments to comply with applicable state biometric privacy statutes, including BIPA consent and retention requirements, and should allocate liability for non-compliance. The policy's reference to 'our service providers' as biometric collectors indicates the company relies on third-party vendors for this function, which creates vendor assessment obligations. 5. COMPLIANCE CONSIDERATIONS: Legal teams should identify which identity verification vendor performs biometric collection, assess that vendor's BIPA and state biometric law compliance posture, review whether written consent is obtained from Illinois residents prior to biometric collection, confirm that a publicly available biometric retention and destruction policy exists, and evaluate whether service provider agreements include appropriate biometric data handling obligations and indemnification provisions.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision authorizes collection of biometric information, a category subject to distinct state biometric privacy statutes including the Illinois Biometric Information Privacy Act, which impose specific consent, retention, and destruction obligations that may apply depending on user location.
The agreement authorizes collection and use of biometric information by the company or its service providers for identity verification purposes. State biometric privacy laws including BIPA in Illinois and comparable statutes in Texas and Washington may impose written consent, retention schedule, and destruction requirements for this data collection.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Hims & Hers.