Biometric Privacy Policy

Effective Date: 23 July 2026

This Biometric Privacy Policy (the “Biometric Policy”) outlines how Checkr collects and processes personal information that may be considered Biometric Data, as defined below. This Biometric Policy supplements our Privacy Policy.

1. When this Biometric Policy Does and Does Not Apply

1.1 What This Biometric Policy Covers

This Biometric Policy applies only to the extent we are processing “biometric identifiers” or “biometric information.” By “biometric identifier,” we mean a scan of your face geometry, such as a facial scan performed on a photograph of you. A “biometric identifier” does not include the photograph itself, just the facial measurements extracted from the photograph. When we say "biometric information,” we mean information converted, stored, or shared based on an individual's biometric identifier used to identify an individual. 

For simplicity, we will refer to biometric identifiers and biometric information together as “Biometric Data.”

1.2 Whom This Biometric Policy Covers

This Biometric Policy applies exclusively to Colorado residents and, to the extent required by applicable law, individuals located in Illinois at the time their Biometric Data were collected.

2. Why We Process Biometric Data and Who Is Involved in That Processing

We use Biometric Data only to help Customers verify identity. To do this, Checkr uses a vendor, Socure, to collect and otherwise process those Biometric Data for us. Checkr does not actually receive, possess, or otherwise have access to your Biometric Data collected by Socure. Rather, Socure notifies Checkr whether it was able to verify your identity based on the Biometric Data and other information it collected from you. Socure’s notification to Checkr is not Biometric Data.

Because Socure is the entity actually collecting your Biometric Data, Socure’s collection, possession, and processing of Biometric Data are subject to its Document & Biometric Verification Privacy Notice. If you would like a detailed account of how Socure processes Biometric Data, we recommend that you read that notice.

3. How Socure Retains and Destroys Biometric Data

Checkr instructs Socure to keep Biometric Data only as long as necessary to fulfill the purpose for which the Biometric Data were processed. Checkr has instructed Socure not to keep Biometric Data beyond two years from the date Socure performed the identity verification. This retention period may be adjusted if permitted or required by applicable law, such as responding to a warrant or court order. If you have questions about the details of how Socure retains, secures, or disposes of your Biometric Data, please read Socure’s Document & Biometric Verification Privacy Notice.