Credence ID Product & Services Privacy Policy

Effective Date: October 1, 2026  ·  Last Updated: October 1, 2026

Credence ID, LLC (“Credence ID,” “we,” “us,” or “our”) provides enterprise identity verification software, mobile applications, cloud services, and hardware platforms to business and government customers. When we provide these products, we act as a service provider and data processor that handles personal data on our customers’ behalf and on their documented instructions. We are committed to maintaining strict data security and support our customers’ own privacy obligations.

This Product & Services Privacy Policy explains how we handle personal data in connection with our identity verification products (“Products”), which we provide to and operate on behalf of our Enterprise Customers. It applies to the following Products:

  • Verify with Credence™ (VwC™) SaaS management portal and web applications;
  • Tap2iD Mobile™ application and mobile software development kits (SDKs);
  • Tap2iD™ Cloud SDK and cloud verification APIs; and
  • Tap2iD™ Verifier physical hardware and embedded software devices.

Important Distinction: This policy governs our products, services, and software applications. If you are a visitor browsing our marketing website (www.credenceid.com), submitting a lead-capture webform, or subscribing to marketing emails, please refer to our separate Privacy Statement at www.credenceid.com/privacy-statement.

Our Role as a Data Processor

In providing our Products to business clients, government entities, and enterprise partners (our “Enterprise Customers”), Credence ID acts primarily as a Data Processor (or Service Provider as defined under applicable privacy laws).

Our Enterprise Customers act as the Data Controllers (or Businesses) who determine the purposes and means of processing, establish the lawful basis for collecting and verifying identity information, and bear the direct consumer-facing privacy obligations. Credence ID processes personal data solely on behalf of, and according to the documented instructions of, our Enterprise Customers, as established in our Master Services Agreements (MSAs) and Data Processing Addenda (DPAs). Enterprise Customers may request a copy of our standard DPA by contacting privacy@credenceid.com.

Where Credence ID Acts as a Controller

In most cases we act as a processor for an Enterprise Customer, as described above. In a limited set of cases we operate a verification experience directly — for example product demonstrations, evaluation and sandbox environments, and our own websites or applications where Credence ID is itself the party requesting a credential. In those cases there is no Enterprise Customer behind the request, and Credence ID acts as the controller (or business) for that verification.

Where we act as controller, we process the credential data solely to perform the verification and display its result to you, we do not retain that data beyond the session, and we do not use it for marketing, profiling, or to train, develop, or improve any model. If your credential was verified in a Credence ID–operated experience of this kind, you may exercise your privacy rights by contacting us directly at privacy@credenceid.com.

Legal Bases and Sensitive Personal Information

  • Lawful basis (GDPR / UK GDPR). As a processor, Credence ID does not independently determine the lawful basis for processing identity data. Our Enterprise Customer, as controller, is responsible for establishing a lawful basis under Article 6 and, where the data includes biometric or other special-category data, an appropriate condition under Article 9 (for example, explicit consent or substantial public interest). Credence ID processes such data only on the controller's documented instructions and for the limited purpose of performing the verification service.
  • Sensitive and special-category data (CCPA/CPRA). Some data we process on our customers' behalf is "sensitive personal information" under the CCPA/CPRA and comparable state laws, including government identification numbers, identity-document images, and the facial image. Credence ID uses this information solely to perform the identity-verification service requested by the Enterprise Customer and for the limited purposes permitted to a service provider. We do not use or disclose sensitive personal information to infer characteristics or for any purpose other than those permitted under applicable law, and we operate within the service-provider exemption such that a separate consumer "Right to Limit" request is directed to and handled by the Enterprise Customer as the business.

Information We Process

The personal information we process depends on the specific products, features, and verification workflows configured by our Enterprise Customer.

Identity & Verification Data (Processed on Behalf of Customers)

When an end-user presents an identity document or digital credential for verification, we may process:

  • Government Identifiers & Credentials: Mobile driver’s license (mDL) attributes, physical and digital ID credentials, passport/ID document images, name, date of birth, address, and document numbers.
  • Verification & Facial Data: The facial image captured or presented alongside the credential, processed to confirm the credential is authentic and genuinely present. Credence ID captures and transmits this image to the Enterprise Customer but does not perform facial recognition or biometric matching and does not generate, derive, or store any biometric template or identifier from it. Where enabled by the Enterprise Customer, any facial matching or age-assurance decision is performed by, or under the sole direction of, the Enterprise Customer.
  • Cryptographic & Trust Signals: Cryptographic signatures, issuing authority trust status (e.g., pass/fail validation), and anti-tamper check results.

Administrative & Account Data

For authorized personnel of our Enterprise Customers who access our management portals:

  • Account Identifiers: Name, business email address, role, login credentials, and multi-factor authentication details required to access our Products.

System Telemetry & Diagnostic Data

To maintain service security, operational reliability, and platform performance:

  • Device & Technical Identifiers: IP address, browser type, operating system, device model, hardware serial number, app version, error logs, and transaction performance metrics. Telemetry data excludes end-user identity attributes or document images.

How We Use Processed Data

We process personal data strictly to provide, secure, and maintain our services in accordance with our agreements with Enterprise Customers:

  • Identity Verification & Authentication: Executing real-time document validation, credential attribute parsing, and cryptographic trust checks, and transmitting the credential data and facial image to the Enterprise Customer. Any facial matching or one-to-one/one-to-many comparison is initiated and performed by the Enterprise Customer, not by Credence ID.
  • Customer Support & Diagnostics: Troubleshooting technical issues, investigating platform errors, and maintaining API availability.
  • Security & Fraud Prevention: Detecting malicious activity, unauthorized access, injection attacks, or system misuse.
  • Account Administration: Managing user access rights and security settings for client administrators logging into our Products.

We do not sell personal data, share personal data for cross-context behavioral advertising, or use verification payload data for third-party marketing or profiling.

Biometric Data

  • Our products capture and transmit the facial image contained in or presented with a credential so that the Enterprise Customer can confirm the credential and, where the Enterprise Customer chooses, perform its own facial matching or age assurance. Credence ID does not perform facial recognition or biometric matching, and does not generate, derive, collect, store, or retain any "biometric identifier," "biometric information," or biometric template (such as a faceprint or facial geometry) as those terms are defined under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Washington biometric statute (RCW 19.375), the Texas Data Privacy and Security Act (TDPSA), or comparable laws.
  • Because Credence ID does not create or retain a biometric identifier or template, the written-release, notice, and retention-and-destruction-schedule obligations that these biometric laws impose on entities that collect or store biometric identifiers do not apply to Credence ID in respect of this service. Where any biometric identifier is created (for example, if the Enterprise Customer elects to perform facial matching), the Enterprise Customer is the entity that collects and controls that biometric data and is responsible for providing any required notice, obtaining any required written consent or release, and maintaining a compliant retention and destruction schedule.
  • Credence ID does not use the facial image, identity documents, or any verification data to train, develop, test, or improve any facial recognition, machine learning, or artificial intelligence model.

Disclosure of Personal Data

We share personal data only in limited circumstances necessary to fulfill our service obligations:

  • Enterprise Customers: Verification results, trust signals, and requested identity attributes are transmitted directly to the Enterprise Customer that initiated the verification request.
  • Authorized Service Providers (Sub-processors): We engage trusted cloud infrastructure providers and secure hosting facilities to operate our cloud APIs and management portals. All sub-processors are bound by strict contractual data protection and security requirements consistent with our obligations to Enterprise Customers. A current list of our sub-processors is available on request from privacy@credenceid.com.
  • Legal & Regulatory Requirements: We may disclose information if required by law, court order, or lawful government demand. When legally permissible, we notify the impacted Enterprise Customer prior to responding.
  • Corporate Transactions: In the event of a merger, acquisition, reorganization, or sale of assets, subject to standard confidentiality protections. Any successor or acquirer will remain bound by the data protection commitments in the applicable Data Processing Addendum with respect to personal data processed on behalf of Enterprise Customers.

Data Security

Credence ID maintains an ISO/IEC 27001:2022 certified Information Security Management System (ISMS) governing our software engineering, cloud infrastructure, and device manufacturing operations.

We implement technical, administrative, and physical safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration:

  • Encryption: Data in transit across public networks is protected using standard cryptographic protocols (TLS). Account data at rest is encrypted using strong encryption standards.
  • Access Control: Access to production infrastructure and client management tools is restricted to authorized personnel using multi-factor authentication (MFA) and least-privilege role-based access controls (RBAC).
  • Security Testing: We conduct regular vulnerability assessments and independent third-party penetration testing (VAPT) across our applications, APIs, and cloud environments.

Data Retention

  • Identity & Verification Payload Data: Verification payloads, decrypted identity attributes, and the facial image are processed ephemerally in memory solely to execute real-time cryptographic validation and pass-through to the Enterprise Customer. Credence ID does not retain, store, sell, or rent this data for its own purposes, and does not use it to train, develop, or improve any facial recognition, machine learning, or artificial intelligence model. Retention of verification results is governed strictly by the instructions and retention schedules established by the Enterprise Customer in our executed agreement.
  • Administrative Accounts: Retained for the active duration of the Enterprise Customer’s contract and purged following account termination.
  • Operational Telemetry: System logs, diagnostic telemetry, and performance metrics are retained only for as long as necessary to maintain platform security and reliability, typically up to 90 days.

Individual Privacy Rights & End-User Inquiries

Because Credence ID processes verification data on behalf of our Enterprise Customers (who are the controllers and businesses responsible for consumer-facing obligations), individuals exercise their privacy rights with the Enterprise Customer that initiated the verification. Depending on where an individual resides, those rights may include the right to know or access, the right to correct, the right to delete, the right to data portability, the right to opt out of sale or sharing and of certain profiling, the right to limit the use of sensitive personal information, and the right to non-discrimination for exercising these rights, as well as the GDPR/UK GDPR rights to object and to restrict processing.

  • End-User Inquiries: If you are an individual whose identity document, digital credential, or facial image was verified using Credence ID technology, please direct your privacy requests (for example, access, correction, or deletion requests) to the business or government entity (the Data Controller) that conducted the check. If you contact us directly, we will refer your request to the relevant Enterprise Customer or, where required, assist that customer in responding. Where the verification was performed in a Credence ID–operated experience, as described in “Where Credence ID Acts as a Controller” above, contact us directly at privacy@credenceid.com.
  • Customer Assistance: We assist our Enterprise Customers in fulfilling valid data subject and consumer rights requests in accordance with applicable global and U.S. state privacy laws, including the EU GDPR, UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the Texas Data Privacy and Security Act (TDPSA), the Washington My Health My Data Act and RCW 19.375, and other comparable state and international privacy laws (including India's DPDPA).

International Data Transfers

Our cloud infrastructure and services are hosted in secure data center regions. Where personal data, including verification-payload data processed on behalf of an Enterprise Customer, as well as administrative and technical support data, is transferred internationally (for example, between the EEA, UK, or Switzerland and the United States), we rely on approved transfer mechanisms, such as the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or UK Addendum, and the Swiss Standard Contractual Clauses, together with any supplementary measures required by applicable law. Because verification-payload data is processed transiently and is not stored by Credence ID, any such transfer is momentary and incident to real-time verification.

Children's Privacy

Our Products are intended for business professionals and adults aged 18 and over. We do not knowingly collect personal information from anyone under 18, and we will delete any such information if we become aware of it.

Updates to This Privacy Policy

We may update this Product & Services Privacy Policy periodically to reflect enhancements in product features, operational practices, or legal compliance requirements. When updates are published, we will revise the "Last Updated" date at the top of this policy. Material changes will be communicated directly to Enterprise Customers via administrative account channels.

Contact Us

If you have questions or concerns about this policy or our privacy practices, please contact our Privacy Team:

Credence ID, LLC
Attn: Privacy Team
1440 Broadway, Suite 850
Oakland, CA 94612, USA
privacy@credenceid.com
+1-888-243-5452