BIPA Notice
Version 2026-10-04 · Effective October 4, 2026
This Notice is posted publicly in compliance with the Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq. ("BIPA"). It describes the biometric data BarMatch causes to be collected through its Services, the purposes for which we collect it, our retention and destruction schedule, and the rights of Illinois residents under BIPA.
This Notice is incorporated by reference into the BarMatch Privacy Policy and Terms of Service. By using BarMatch features that involve biometric processing (described below), you consent to the practices described in this Notice. Capitalized terms not defined here have the meanings given in the Privacy Policy.
1. Definitions
"Biometric identifier" has the meaning set forth in 740 ILCS 14/10, including a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. "Biometric information" means information based on a biometric identifier used to identify an individual. Together, biometric identifiers and biometric information are referred to in this Notice as "biometric data."
BarMatch does not collect, scan, or store biometric data directly. Two BarMatch features cause biometric data to be processed by service providers acting on our behalf, and on your behalf, as described below.
2. Biometric data processed through the Service
2.1 Identity verification (Persona)
When a user verifies their identity on BarMatch ("Verify Your ID" — free during the launch period; thereafter a $0.99 one-time in-app purchase, never a subscription, that goes toward Persona's charge for each check and is set below it), our identity-verification partner Persona Identities, Inc. ("Persona") collects:
Identity verification is required to participate in the Match Game (browsing, liking, and matching with other users). Verification is never required for — and never gates — venue discovery, Deals, or Friends features.
- A photograph of the user's government-issued ID;
- A live selfie taken at verification time; and
- Face geometry derived from both images to confirm the photo on the ID matches the selfie.
Persona is the data controller and retention party for that biometric data. BarMatch receives only the verification result, the user's legal name, date of birth, gender, and a Persona inquiry ID for audit purposes. BarMatch does not store the government-ID image or the verification selfie. For the separate face-match feature described in Section 2.2, BarMatch — only after obtaining the user's prior written consent as described in Section 4 — briefly processes a copy of the verification selfie once to derive a numeric face-geometry vector via AWS Rekognition, and then discards the selfie image. BarMatch retains only the mathematical vector, never the ID image or the selfie image. The vector is used strictly for the two purposes described in Section 3: (a) confirming that the user's profile photos depict the same verified person, and (b) detecting duplicate accounts.
Persona's own retention practices, security standards, and biometric-data handling policies are available at: withpersona.com/legal/privacy-policy.
2.2 Profile photo face-match (Amazon Rekognition)
For users who have completed identity verification, BarMatch causes face geometry to be compared between each photo the user uploads to their BarMatch profile and the face-geometry vector derived from that user's verification selfie. The face-comparison operation is performed by Amazon Web Services, Inc.'s Rekognition service ("AWS Rekognition") acting as a service provider on BarMatch's behalf.
Specifically:
- BarMatch maintains, for each verified user who has consented, a face-geometry vector (a numerical representation derived from the user's verification selfie) within an AWS-managed Rekognition Face Collection. The selfie image itself is not retained by BarMatch (see Section 2.1).
- At each profile photo upload, BarMatch sends the uploaded photo to AWS Rekognition, which derives a face-geometry vector for the uploaded face and compares it to the stored face-geometry vector for that user.
- If the comparison meets BarMatch's configured similarity threshold, the photo may appear publicly on the user's profile. If it does not match, the photo is hidden from public view — it is retained privately in the user's account (it is not deleted) and is not shown to other users until the user replaces it with a photo that does match. There is no self-serve override to publish a non-matching photo; a user who believes a photo was hidden in error may contact support@barmatch.com to request manual human review. At least one matching, publicly visible photo is required for a user to appear in the Match Game.
- The stored face-geometry vector is also used to detect duplicate accounts — i.e., to identify when the same verified face is associated with more than one BarMatch account.
- BarMatch does not retain copies of the face-comparison probe images outside of the brief duration needed to perform the comparison; the long-lived store is only the face-geometry vector derived from the user's verification selfie.
Users who have not completed identity verification do not have face-geometry vectors stored. Photos uploaded by unverified users undergo content moderation (an explicit-content scan that does not derive biometric data) and perceptual-hash duplicate detection (a non-biometric image-similarity check that compares against existing photos on the platform), but no face-comparison is performed.
AWS's practices, including its data-handling and security certifications as applied to the Rekognition service, are described in its public documentation: aws.amazon.com/rekognition and aws.amazon.com/compliance.
3. Purpose of collection
Biometric data is processed through the Service for the sole purpose of confirming user identity integrity:
- Identity verification (Persona). To confirm that the person whose government-issued ID is presented at signup is the same person taking the verification selfie, and that the person is at least 21 years of age. This underpins BarMatch's 21+ requirement and the "verified" status displayed on user profiles.
- Profile photo face-match (AWS Rekognition). To confirm that profile photos uploaded by a verified user depict that same verified user, preventing identity misrepresentation (commonly "catfishing") within BarMatch's social and transactional features.
- Duplicate-account detection (AWS Rekognition). To detect when the same verified face is associated with more than one BarMatch account, preventing duplicate accounts and evasion of suspensions or bans.
Biometric data is not used for advertising, marketing, targeting, profile recommendations, or any commercial purpose other than the identity-integrity purposes above. Biometric data is not sold, leased, traded, or otherwise commercially exchanged with any third party.
4. Written informed consent
BarMatch obtains written informed consent from each user before any biometric data is collected through our Services, as required by 740 ILCS 14/15(b). Consent is obtained in-app before any biometric data is created or collected, before verification completes, and before any verification fee is charged. A user who declines consent is never charged, and no biometric data is created for that user.
4.1 Consent for identity verification (Persona)
Prior to initiating the Persona identity verification flow, the user is presented with an in-app consent screen identifying:
- That biometric data will be collected and processed;
- The specific biometric data collected (ID image, selfie, and face geometry derived from both);
- The purpose of collection (age verification and identity confirmation);
- The retention period (per Persona's data processing agreement and applicable law, with the BarMatch-side audit identifier retained for the duration of the user's BarMatch account);
- Persona's role as the data controller and retention party for the underlying biometric data.
The user must affirmatively tap a "Verify My Identity" button to proceed. Tapping the button constitutes the user's written release authorizing Persona to collect and process the biometric data described above.
4.2 Consent for BarMatch's face-geometry vector and profile photo face-match (AWS Rekognition)
Before BarMatch derives the face-geometry vector from the user's verification selfie — that is, before verification completes and before any verification fee is charged — the user is presented with an in-app BIPA consent screen identifying:
- That a numeric face-geometry vector will be derived from the verification selfie via AWS Rekognition, and that the selfie image itself will not be retained by BarMatch;
- That the vector derivation and all subsequent face comparisons are performed by Amazon Web Services Rekognition as a service provider on BarMatch's behalf;
- The purposes of collection (confirming that the user's profile photos depict the same verified person, and detecting duplicate accounts — see Section 3);
- That each profile photo the user uploads will be compared against the stored vector, and that photos that do not match will be hidden from public view until replaced (see Section 2.2);
- The retention period set forth in Section 5 below;
- The destruction schedule set forth in Section 6 below;
- That the user may decline. If the user declines, no biometric data is created or collected by BarMatch, no verification fee is charged, and the user does not complete verification and cannot participate in the Match Game. Declining does not affect the user's access to venue discovery, Deals, or Friends features.
The user must affirmatively tap an "I Consent" button to proceed; the face-geometry vector is created only after that affirmative act. The consent record (date, time, user ID, and consent version) is logged immutably and retained for the duration of the user's BarMatch account plus three (3) years thereafter, per BIPA's general record-keeping expectations. Consent may be withdrawn at any time in the app under Account → Privacy; withdrawal triggers permanent deletion of the vector as described in Section 6.
5. Retention schedule
In compliance with 740 ILCS 14/15(a), BarMatch maintains the following public retention schedule for biometric data processed through our Services:
- Persona-held biometric data (ID image, selfie, and face geometry derived from them). Retained by Persona in accordance with their data processing agreement, their privacy policy (withpersona.com/legal/privacy-policy), and applicable law. BarMatch does not separately control Persona's retention period.
- BarMatch-held face-geometry vector (in AWS Rekognition Face Collection). Retained until the earliest of: (a) the user withdraws biometric consent (in-app under Account → Privacy, or by request to privacy@barmatch.com); (b) thirty (30) days after the user's account is closed; or (c) the user is dormant (no app login) for three (3) consecutive years. At the earliest of these triggers, the vector is permanently deleted per Section 6.
- Probe images (uploaded profile photos as part of the face-match call). Not retained beyond the duration needed to perform the comparison (approximately seconds). AWS Rekognition does not store these images by default; BarMatch's integration does not request retention. Profile photos themselves (including photos hidden from public view pending replacement, per Section 2.2) are stored as user-account content in the user's profile under the Privacy Policy's general retention rules — but these are stored as image files, not as biometric data, and no face-geometry vector derived from an uploaded profile photo is retained after the comparison completes.
- Consent records. Retained for the duration of the user's account plus three (3) years thereafter (a typical statute-of-limitations buffer).
6. Destruction schedule
In compliance with 740 ILCS 14/15(a), BarMatch destroys biometric data on the following schedule:
- On consent withdrawal: a user may withdraw biometric consent at any time in the app under Account → Privacy (or by written request per Section 9). On withdrawal, the BarMatch-held face-geometry vector is permanently and irreversibly deleted from the AWS Rekognition Face Collection. After withdrawal, the user can no longer participate in the Match Game (which requires a verified, face-matched profile) unless they later re-verify and re-consent; venue discovery, Deals, and Friends features are unaffected.
- On account closure: the BarMatch-held face-geometry vector is permanently and irreversibly deleted from the AWS Rekognition Face Collection no later than thirty (30) days after the user's account is closed.
- On dormancy: if a user does not log in to their BarMatch account for three (3) consecutive years, the BarMatch-held face-geometry vector is permanently and irreversibly deleted at the end of that period, regardless of whether the account remains open. The user's account is flagged for re-consent at next login if they wish to continue participating in the Match Game.
- On user request: a user may at any time request immediate destruction of their BarMatch-held biometric data by contacting privacy@barmatch.com (subject line "Illinois BIPA destruction request"). BarMatch will honor such requests within thirty (30) days. For Persona-held biometric data, BarMatch will forward the request to Persona and provide the user with Persona's contact for direct follow-up.
- On BIPA repeal or expiration of business need: if at any point BarMatch ceases to require the face-match feature, or if BIPA is repealed and no comparable applicable law applies, BarMatch will destroy all BarMatch-held biometric data within sixty (60) days.
7. Disclosure restrictions
In compliance with 740 ILCS 14/15(d), BarMatch does not sell, lease, trade, or otherwise profit from biometric data processed through our Services. BarMatch does not disclose, redisclose, or otherwise disseminate biometric data except:
- To service providers (Persona and Amazon Web Services) collecting and processing the biometric data on BarMatch's behalf and on the user's behalf for the purposes described in this Notice;
- With the user's separate written authorization, in the event a specific further use is requested;
- To comply with a valid warrant, subpoena, or court order issued by a court of competent jurisdiction; or
- As required by federal, state, or local law or municipal ordinance.
8. Standard of care
In compliance with 740 ILCS 14/15(e), BarMatch and its service providers store, transmit, and protect from disclosure all biometric data using the reasonable standard of care within the technology industry, and in a manner that is the same as or more protective than the manner in which we store, transmit, and protect other confidential and sensitive information. Specifically:
- AWS Rekognition Face Collections are hosted in encrypted, access-controlled AWS data stores subject to AWS's SOC 2 Type II, ISO 27001, and other industry-standard security certifications.
- Access to the BarMatch face-comparison API is restricted to BarMatch service-role credentials; user-side application code cannot directly query the Face Collection.
- Persona biometric data is stored in Persona's SOC 2 Type II certified infrastructure per their data processing agreement.
- Consent records and audit logs are stored in BarMatch's primary database (PostgreSQL via Supabase), subject to row-level security policies that restrict access to platform administrators only.
9. Your rights under BIPA
Illinois residents may at any time:
- Request information about biometric data we cause to be collected from you, the purpose of collection, and our retention schedule.
- Withdraw consent to biometric processing at any time, in the app under Account → Privacy or by contacting privacy@barmatch.com. On withdrawal, the BarMatch-held face-geometry vector is permanently deleted (see Section 6); you will no longer be able to participate in the Match Game unless you later re-verify and re-consent, but your account and your access to venue discovery, Deals, and Friends features are unaffected.
- Request immediate destruction of biometric data we hold about you. We will honor this request within thirty (30) days for data BarMatch directly controls. For data held by Persona, we will forward the request and identify Persona's contact for direct follow-up.
- Request a copy of this Notice in an alternative format if you have an accessibility need; contact privacy@barmatch.com with subject "Accessible BIPA Notice".
Send BIPA-related requests to privacy@barmatch.com with "Illinois BIPA request" in the subject line, or by mail to:
BarMatch LLC, Attn: Privacy
980 N MICHIGAN AVE STE 1090 # 943505
CHICAGO, IL 60611
BarMatch will respond to verifiable BIPA requests within thirty (30) days.
10. Changes to this Notice
BarMatch may update this Notice from time to time to reflect changes in our practices, new service providers, or changes in applicable law. When we make material changes, we will notify affected Illinois users through the app, by email, or by an in-app banner before the change takes effect, and will revise the "Last updated" date at the top of this Notice.
11. Effective date
This Notice is effective as of the "Last updated" date above and applies to all biometric data processed through the BarMatch Service on or after that date, as well as biometric data already in our (or our service providers') possession at that time.