Privacy & compliance

How biometric data is collected, stored, and handled.

Biometric verification only helps a tax practice if it can be explained to a client and defended to a regulator. This page describes how Verafile handles identity data as the system is designed, so you can reference it in your WISP and your client notice.

What is collected

  • A capture of the government-issued ID presented at intake (front, back, and the raw 2D PDF417 barcode data).
  • A short live facial capture used for liveness detection and comparison against the ID portrait.
  • The derived face template — a mathematical representation used only for the match. It is not a stored photograph and cannot be reversed into one.
  • Check metadata: timestamps, device and location of capture, the match result, and the risk reasons shown on your dashboard.

Consent before capture

  • The taxpayer sees a plain-language biometric notice and must affirmatively consent before any capture begins.
  • The notice states what is collected, why, how long it is kept, and that it is not sold or shared.
  • Consent is recorded with a timestamp and stored alongside the verification record as evidence for your file.
  • A taxpayer may decline. Your office can then fall back to your existing manual identity procedure — Verafile records the decline rather than a result.

How it is stored

  • Encrypted in transit (TLS) and at rest. Face templates are stored separately from taxpayer PII and are linked only by an internal identifier.
  • Access is role-scoped to your office. Staff at other offices cannot view your captures — cross-office fraud intelligence shares risk signals and pattern flags, never images or templates.
  • Every read, export, and deletion is written to an immutable access log available to you.

Retention and deletion

  • Retention is configurable per office. Raw ID and face captures default to a short retention window; the verification result and audit record are kept for the period your recordkeeping obligations require.
  • You can delete an individual client's biometric captures at any time from the dashboard; the audit entry that a check occurred remains, without the underlying imagery.
  • On account termination, biometric data is deleted on the schedule set out in your agreement.

What is never done

  • Biometric data is never sold, licensed, or shared for advertising.
  • It is never used to train third-party models.
  • It is never disclosed to law enforcement without valid legal process, and you are notified where the law permits.

Your responsibilities as a preparer

  • Reference biometric verification in your WISP and in your client privacy notice.
  • Use the built-in consent flow rather than capturing IDs by text, email, or personal phone.
  • Set a retention window appropriate to your state — several states (including Illinois, Texas, and Washington) impose specific biometric consent and retention duties.
  • Verafile provides the tooling and the evidence trail; the identity decision, and the relationship with your client, stay yours.

Questions about a specific requirement?

Email hello@getverafile.com or request a demo and we'll walk through the consent flow and retention settings for your state.

Request a biometric verification demo

This page describes the system as designed and prototyped and is provided for information only. It is not legal advice, and Verafile, Inc. is not a law firm.