Legal · Biometric Data

Biometric Data Policy

Last updated: July 23, 2026

This policy explains how RollCall — operated by RollCall - NightLife, Inc., a Delaware corporation — handles biometric data in connection with optional ID verification. We publish it because laws like the Illinois Biometric Information Privacy Act (BIPA) require a written, publicly available policy describing our retention schedule and our guidelines for destroying biometric data. It applies to everyone who chooses to verify their ID, everywhere we operate.

The one-sentence version: if you choose to verify your ID, your ID photo and selfie go directly to our verification provider (Stripe) — they never reach RollCall — and RollCall never collects, receives, stores, or has access to your face-geometry data or any other biometric identifier at any point.

What this covers

ID verification is optional. You can use RollCall fully without it. If you choose to verify, you photograph your government ID and take a selfie, and our verification provider compares the selfie to the photo on the ID to confirm the ID is yours. Making that comparison creates a scan of face geometry — a "biometric identifier" under BIPA and similar laws. This policy governs that data.

This policy does not apply to RollCall's venue crowd features. Room scans and walkthrough videos count people and never identify anyone — no facial recognition, no face matching, no biometric identifiers of any kind. That commitment is separate and unchanged.

Who holds the biometric data

Our verification provider is Stripe, Inc., through Stripe Identity. When you verify:

Stripe processes this data as a service provider under its own agreements and privacy terms. Stripe's handling is described at stripe.com/privacy.

Why we verify

Two purposes, both described here and in our Privacy Policy. First, to confirm that you are 21 or older and that the ID belongs to you — so you can skip the in-app birthday check when you buy cover. Second, the coarse summary above is used only in aggregate, to understand which nights and venues suit which crowds and where to open next. We do not use verification, or anything derived from it, for advertising, profiling, or tracking, and we never use it to decide who gets into anywhere.

Consent

We ask for your informed consent before any capture begins, on a dedicated screen that tells you what happens, why, who receives the data, and how long it is kept. Verification does not start unless you agree. You may decline — declining costs you nothing but the optional benefit, and you keep using RollCall exactly as before, with the usual birthday check when you buy cover.

Retention schedule & destruction

RollCall retains no biometric data at any point, because we never receive it. What we keep is the verification result and the short coarse summary described in "Who holds the biometric data" above — a "verified" status, a "21 or older" yes/no, a broad age range, the sex marker printed on the document, the kind of document, its country and state, timestamps, and an opaque reference. None of that is a biometric identifier or derived from one. We keep it while your account is active, and it expires and must be renewed after 365 days.

For the biometric data held by our provider, our destruction guideline is: destroyed as soon as the verification is complete — normally within minutes, and generally no later than 30 days after your verification session. We instruct Stripe to redact (permanently delete) the ID images and associated data as soon as we receive the result, and again if you withdraw consent or delete your account; if a session is abandoned or fails, an automated daily job requests that deletion within days. This schedule is far shorter than the maximum any applicable law permits (for example, BIPA's outer limit of three years from your last interaction), and we destroy on the earlier of "purpose satisfied" or that short window.

How we protect it

The strongest protection is architectural: we designed the flow so the biometric data never touches RollCall's systems at all — there is no bucket, database, or log where an ID image or face template could sit. Where data is handled by our provider, it is transmitted and stored using the reasonable standard of care for our industry and in a manner at least as protective as we treat other confidential information.

Your choices & rights

State-specific notes

This policy is written to satisfy, at minimum, the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, and Washington's biometric law, as well as the "sensitive personal information" provisions of the California Consumer Privacy Act as amended. Where any applicable law requires more, that law controls. We do not sell or lease biometric data, we do not disclose it except as needed to complete the verification you requested or as required by law, and we do not use it for any purpose beyond the verification you consented to.

Changes

We'll update this page and the "last updated" date when this policy changes. If a change materially affects how biometric data is handled, we will ask for renewed consent before it applies to you.

Questions about this policy or your data? Contact [email protected] — a human reads it.