Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Revolut collects sensitive categories of personal data, which may include biometric information used for identity verification purposes such as facial recognition or fingerprint authentication.
This analysis describes what Revolut's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Biometric data such as facial scans or fingerprints is highly sensitive because, unlike passwords or account numbers, it cannot be changed if compromised, making its collection and protection particularly significant.
Interpretive note: The specific extent of biometric data collection is inferred from the financial services and identity verification context; the exact policy language on this point was in portions of the document not fully reproduced in the source text.
If Revolut collects your biometric data for identity verification, that information is subject to specific legal protections in several US states, and its exposure or misuse would carry risks that cannot be remediated by simply resetting a credential.
How other platforms handle this
The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
Monitoring
Revolut has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We collect your personal data when you use: our website at www.revolut.com/en-US/; any of our Revolut apps; any of the services available to you through our apps or websiteExcerpt from Revolut's Privacy Policy
REGULATORY LANDSCAPE: Biometric data collection is regulated at the state level in the US, most significantly under the Illinois Biometric Information Privacy Act (BIPA), which requires written notice and consent before collecting biometric identifiers and imposes strict retention and destruction schedules. Texas and Washington have analogous statutes. The CCPA and CPRA classify biometric data as a sensitive personal information category subject to additional disclosure and opt-out rights. No comprehensive federal biometric privacy statute currently exists, though the FTC has addressed biometric data in enforcement actions. GOVERNANCE EXPOSURE: High. Biometric data collection by a financial services platform creates significant exposure under state biometric statutes, particularly BIPA, which provides a private right of action with statutory damages and has generated substantial class action litigation. Even where a user is not physically located in Illinois, questions about where data is processed may affect exposure. JURISDICTION FLAGS: Illinois BIPA creates the most significant litigation exposure due to its private right of action. Texas CUBI and Washington's statute are enforced by state attorneys general. California CPRA requires that consumers be given the ability to limit use of sensitive personal information, including biometric data, which may require a specific opt-out mechanism. CONTRACT AND VENDOR IMPLICATIONS: If biometric data collection is performed by a third-party identity verification vendor, the vendor agreement must address BIPA compliance, data retention limitations, destruction obligations, and prohibition on onward sharing. Procurement teams should verify vendor consent collection processes and data destruction schedules. COMPLIANCE CONSIDERATIONS: A biometric data inventory should be maintained documenting what biometric data is collected, from which users, for what purpose, by which entity, and with what retention schedule. Consent mechanisms for biometric data should be reviewed to ensure they meet the informed written consent standard required under BIPA and analogous statutes. State-by-state applicability assessments should be conducted and updated as new state biometric laws are enacted.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Biometric data such as facial scans or fingerprints is highly sensitive because, unlike passwords or account numbers, it cannot be changed if compromised, making its collection and protection particularly significant.
If Revolut collects your biometric data for identity verification, that information is subject to specific legal protections in several US states, and its exposure or misuse would carry risks that cannot be remediated by simply resetting a credential.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Revolut.