Biometric Information Policy
Effective Date: June 12, 2026
This Policy explains how Smiley Pay Limited collects, uses, stores, retains, protects, and destroys biometric information.
1. What We Collect
Facial photographs, live scans, geometry, templates, embeddings, authentication timestamps, success/failure records.
2. Purpose
Identity verification, authentication, fraud prevention, security, improving accuracy. Never for advertising or sale.
3. Consent
Collected only after voluntary enrollment and affirmative consent. Withdrawal is available at any time by deleting biometric data from your account or by contacting us.
4. Storage
Facial images and derived templates stored with encryption and access controls. Protected by reasonable safeguards.
5. Retention & Destruction
Biometric data is retained for a maximum of 365 days from the date of last authentication activity, or until the earlier of: (a) you delete your biometric data, (b) you close your account, (c) you withdraw consent, (d) your organization terminates service, or (e) the data is no longer necessary for the purpose collected. Upon any of these triggers, all biometric identifiers and biometric information are permanently and irreversibly destroyed within 30 days.
6. Disclosure
Never sold, rented, or traded. Disclosed only to service providers, cloud infrastructure, fraud prevention partners, or when legally required.
7. Contact
Smiley Pay Limited
Website: smileylimited.com
Questions or privacy requests? Get in touch.