Mercury · Mercury Privacy Policy · View original document ↗

Biometric Data Collection

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mercury changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mercury recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Mercury Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes collection of voiceprints, facial scans, and biometrics extracted from photographs for identity verification and related purposes, and classifies this data as Sensitive Personal Information under California law.

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes collection of biometric identifiers that are subject to distinct statutory frameworks in several U.S. states, including Illinois BIPA, Texas CUBI, and Washington state law, which impose written consent, retention schedule, and data destruction requirements beyond what this policy's general language specifies.

Interpretive note: The extent to which Mercury's general consent and retention language satisfies state-specific biometric privacy statute requirements depends on jurisdiction-specific enforcement interpretation and the operational details of Mercury's identity verification workflows, which are not fully described in this policy.

Consumer impact (what this means for users)

The agreement authorizes Mercury to collect voiceprints, facial scans, and photograph-derived biometrics; under applicable state biometric privacy laws, users in Illinois, Texas, and Washington may have rights to prior written consent, defined retention periods, and data destruction that extend beyond the general rights described in this policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Send a privacy deletion request to [email protected] referencing your biometric data. Mercury will verify your identity before processing the request.

Cross-platform context

See how other platforms handle Biometric Data Collection and similar clauses.

Compare across platforms →

Monitoring

Mercury has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Biometric information , such as voiceprint, facial scan, and biometrics extracted from a photograph or image. [...] Under California law, certain information we collect may be considered Sensitive Personal Information, including: [...] Biometric information for the purposes of uniquely identifying a California resident We only use or share Sensitive Personal Information as allowed by law.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages Illinois BIPA (740 ILCS 14), Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington's biometric privacy provisions, each of which imposes specific written consent, retention schedule, and destruction obligations for voiceprints and facial geometry data. The CCPA and CPRA classify biometric data as Sensitive Personal Information subject to purpose limitation and opt-out rights. The FTC's consumer protection authority is also relevant. State attorneys general in Illinois, Texas, and Washington have enforcement authority over biometric privacy statutes. 2) GOVERNANCE EXPOSURE: High. The collection of voiceprints and facial scans without explicitly documented written consent mechanisms, retention schedules, or destruction timelines in this policy creates potential exposure under Illinois BIPA, which provides a private right of action and statutory damages ranging from $1,000 to $5,000 per violation. The policy's general retention language does not specify biometric-specific retention limits required under BIPA. 3) JURISDICTION FLAGS: Illinois creates the highest exposure given BIPA's private right of action. Texas and Washington impose statutory obligations without private rights of action but are subject to state AG enforcement. California's CPRA requires purpose limitation for Sensitive Personal Information. Users located in these states who undergo biometric identity verification should assess whether Mercury's consent mechanisms meet applicable state requirements. 4) CONTRACT AND VENDOR IMPLICATIONS: Mercury discloses biometric data to affiliates and service providers. Procurement teams engaging Mercury as a vendor should assess whether Mercury's biometric data processing agreements with downstream service providers include BIPA-compliant data handling terms, destruction obligations, and prohibition on sale or profit from biometric data. 5) COMPLIANCE CONSIDERATIONS: Legal teams should audit whether Mercury's identity verification workflow includes state-specific written consent capture, particularly for Illinois users. Data mapping should document biometric data retention periods and destruction schedules. Any service provider receiving biometric data should be reviewed for BIPA-compliant contractual obligations. Policy updates may be needed to disclose jurisdiction-specific biometric retention and destruction timelines.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices related to biometric data collection and consumer privacy disclosures
    File a complaint →
  • State AG
    State attorneys general in Illinois, Texas, and Washington enforce biometric privacy statutes applicable to voiceprint and facial scan collection
    File a complaint →

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015750
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f8b49beb208e6c3f2b9fb8ddafa22b88d22bbef9e6d3e086c87840d1d5a282f8
Analysis generated
July 9, 2026 08:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-015750
Captured: 2026-07-09 08:43:59 UTC
SHA-256: f8b49beb208e6c3f…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-015750/biometric-data-collection/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Mercury's Biometric Data Collection clause do?

This provision authorizes collection of biometric identifiers that are subject to distinct statutory frameworks in several U.S. states, including Illinois BIPA, Texas CUBI, and Washington state law, which impose written consent, retention schedule, and data destruction requirements beyond what this policy's general language specifies.

How does this clause affect you?

The agreement authorizes Mercury to collect voiceprints, facial scans, and photograph-derived biometrics; under applicable state biometric privacy laws, users in Illinois, Texas, and Washington may have rights to prior written consent, defined retention periods, and data destruction that extend beyond the general rights described in this policy.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.