🏢 HoopFrog is a brand of HoopFrog Inc. — Federal Corporation No. 1467452-9, Alberta, Canada.

HoopFrog Inc. · Last updated: July 20, 2026

Biometric Privacy Policy

Version: 1.0  |  Effective Date: April 18, 2026

HoopFrog is operated by HoopFrog Inc. ("we", "us", "our"). This policy is adopted pursuant to the Illinois Biometric Information Privacy Act, 740 ILCS 14/15(a) (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington’s H.B. 1493, and, for data subjects located in the European Union or United Kingdom, GDPR Article 9 and UK DPA 2018 requirements relating to special-category data.

1. Purpose of Collection

We collect facial geometry scores during our selfie identity verification process to:

  • Prevent fraudulent signups (bots, catfish accounts, account takeovers);
  • Support age-assurance where the law (UK Online Safety Act 2023, EU DSA, US state laws) requires users to be 18 or over. The age check itself is performed separately by an independent age-assurance provider, not derived from your facial geometry;
  • Protect our community from impersonation by matching a live selfie to the profile photos you upload.

Facial geometry scores are mathematical representations of the spatial relationships between facial landmarks. They are not photographs and cannot be used to recreate your image.

2. Processors and International Transfers

The following sub-processors may process biometric identifiers on our behalf (PhotoDNA excepted , it receives only image hashes and no facial-geometry data). Each is bound by a Data Processing Agreement and, where applicable, Standard Contractual Clauses (SCCs) for cross-border transfers:

  • VerifyMy (United Kingdom) , third-party age-assurance provider. Covered by UK GDPR and the EU→UK adequacy decision. SCCs in place for onward transfers.
  • Amazon Web Services , Rekognition (EU , Ireland, eu-west-1) , face-matching and image-quality/anti-spoofing checks (a still-image selfie photo-match check; the dedicated AWS Face Liveness service is not currently used). Processed under the AWS Data Processing Addendum, with SCCs for any onward transfer, and excluded from AWS AI/ML training.
  • Microsoft PhotoDNA (United States) , image hash matching for illegal-content (CSAM) screening. Covered by SCCs. PhotoDNA receives only image hashes for CSAM matching; it does not receive facial-geometry biometric data.

No biometric identifier is sold, leased, traded, or otherwise profited from. We do not use biometric data for advertising or analytics.

3. Retention Schedule

Biometric identifiers (facial geometry scores) are destroyed when the initial purpose for collection is satisfied (i.e., verification outcome recorded) OR within three (3) years of the individual’s last interaction with the Service, whichever occurs sooner. This complies with BIPA 15(a) "whichever is sooner" standard.

Failed, rejected, or expired verification attempts are purged within 90 days via an automated daily cron job.

Successful verification retains only the outcome flag and a reference identifier; the raw facial geometry score is destroyed immediately after the match result is recorded where the processor’s API permits ephemeral processing.

4. Destruction Process

When retention limits are reached, or at user request:

  • We delete all copies from our own storage (database rows and any derived artifacts).
  • Face-matching uses stateless Rekognition with no face collection, so AWS retains no facial geometry to delete; the selfie exists only transiently and is erased immediately after matching. We delete our own database records and log the deletion event. On full account deletion we issue a VerifyMy erasure request where a data-subject-request endpoint is configured. PhotoDNA holds no biometric data (image hashes only), so there is nothing biometric to delete there.
  • We retain an audit record of the deletion event (without the biometric data itself) to demonstrate compliance.

5. Legal Basis

  • GDPR / UK GDPR: Article 9(2)(a) , your explicit consent, given via the Biometric Consent Release screen before selfie capture begins.
  • BIPA (Illinois): 740 ILCS 14/15(b) , informed written release signed by the data subject, with full disclosure of purpose and retention schedule.
  • Texas CUBI § 503.001 / Washington H.B. 1493: Informed disclosure and consent at the time of collection.
  • PIPEDA (Canada): Meaningful consent under Principle 4.3.

6. Your Rights

You may at any time:

  • Revoke your consent. Go to Settings → Privacy → Revoke biometric consent. Upon revocation we will delete retained facial geometry from our storage and instruct processors to do the same within 7 days. Note: withdrawing consent does not retroactively invalidate lawful processing that occurred prior to withdrawal.
  • Request access to any biometric record we hold about you (GDPR Art. 15, BIPA 15(d)).
  • Request deletion. You may request deletion at any time, independent of consent withdrawal.
  • Request portability of your verification outcome (pass/fail flag) , though the raw facial geometry score is not portable under current sub-processor APIs.

7. Security Safeguards

Biometric identifiers in transit are protected by TLS 1.3. At rest, they are encrypted using AES-256 inside each processor’s infrastructure. Access is restricted to the narrow automated pipeline that performs the face match; no human operator at HoopFrog Inc. views raw biometric data in the ordinary course of business.

8. Contact

Questions, access requests, or consent revocations relating to biometric data:

HoopFrog Inc.
Attn: Privacy Officer (Biometric Requests)
3-11 Bellerose Drive, Suite 312
St. Albert, AB T8N 5C9, Canada
Email: support@hoopfrog.com

9. Changes to This Policy

If we materially change this policy , for example by adding a new sub-processor or extending retention , we will increment the version number and re-prompt affected users for consent before continuing to process their biometric data under the new terms.