Identity verification
Biometric-data notice
When you verify your identity to host a public event, claim a venue listing, or claim an Event Pass, we hand your selfie and government-ID photo to Stripe Identity. Stripe uses those images to derive a biometric identifier that matches your face against your ID. This page explains what that means, who touches what, how long any of it is kept, and how to make it go away.
Consent version: 2026-07-25
What is collected
The identity check captures two items: a photo of a government-issued ID (driver's license, passport, or equivalent) and a selfie photo taken by your device camera. From those images, Stripe Identity derives a biometric identifier — a mathematical representation of the facial geometry visible in the selfie and on the ID — and compares the two to confirm they represent the same person.
Full Uproar Games and Gamestead do not capture, process, or store the raw selfie, ID image, or biometric identifier ourselves. From Stripe we receive only: a pass/fail signal, the name / date-of-birth / address fields Stripe extracted from your ID, and (for age-gated features) a coarse over-18 boolean.
Who collects and stores it
Stripe, Inc. collects and stores the images and the derived biometric identifier as an independent controller. Their handling is governed by the Stripe Identity Privacy Policy, which Stripe presents at the point of capture on their own consent screen. Review it before you consent:
Purpose
The biometric identifier is used only to verify your identity for the feature you invoked. Those features are:
- Publishing a public event you host personally.
- Claiming a venue listing on Full Uproar or Gamestead.
- Displaying a Business Verified badge on a venue.
- Claiming an Event Pass to an age-gated (18+) public event.
- Progressing to a higher trust tier that unlocks the above.
We do not use the biometric identifier, or the pass/fail signal we receive back, for advertising, ranking, profiling, model training, or any purpose other than identity verification and related fraud prevention for the feature you invoked.
Retention schedule
Stripe retains the biometric identifier for as long as needed to provide the verification service, and destroys it in accordance with its retention policy. Refer to Stripe's privacy documentation linked above for the current retention window that applies to your session.
On our side, we retain the pass/fail signal, the extracted name / DOB / address fields, the timestamp of the check, and the BiometricConsentReceipt (the record that you saw and accepted this notice at a specific version) for the duration of the relationship the check unlocked — for as long as your account is active, or the venue you claimed remains under your care, or the event you hosted has legal reporting obligations attached. When that relationship ends, we destroy those records within 90 days unless a legal-hold, tax, or fraud-investigation obligation requires a longer retention, in which case we destroy them at the end of that obligation.
Destruction guidelines
When retention expires, or when you request deletion (see the “Right to withdraw” section below), we destroy the pass/fail signal, extracted fields, and consent-receipt row on our side and forward your deletion request to Stripe so Stripe can destroy the underlying biometric identifier they hold. Stripe's own destruction procedures are described in the Stripe Identity documentation linked above; broadly, Stripe deletes the biometric identifier via automated purging on the schedule described in their BIPA disclosure or, on a user request routed through us, sooner.
No sale, lease, or trade
We do not sell, lease, trade, or otherwise profit from your biometric identifier. We also do not sell, lease, or trade the pass/fail signal, the extracted identity fields, or the consent-receipt record derived from your identity check.
Third-party disclosure
We do not share your biometric identifier with any third party other than Stripe. Stripe may share it with subprocessors it uses to render its identity-verification service (for example, cloud infrastructure Stripe operates on and, in some cases, document-verification vendors Stripe engages). Stripe's subprocessor list and disclosures are governed by the Stripe documents linked above.
We may disclose the pass/fail signal and extracted identity fields (not the biometric identifier — we never receive it) to comply with a valid legal process, respond to a lawful request from a law-enforcement agency, or protect the safety of a person or the integrity of the platform. Any such disclosure is scoped to what the process requires.
Right to withdraw
You can withdraw consent at any time. Withdrawing consent terminates the verification (if in progress) and, if verification has already completed, revokes the features it unlocked (event hosting, venue claim, business badge, Event Pass claim, trust-tier progression). You cannot un-verify an event that has already happened, but future access to those features is revoked.
To withdraw consent or request deletion of the pass/fail signal and extracted fields we hold, use the Privacy Choices control surface on your account, or email privacy@fulluproar.com with the subject line “Biometric data deletion request” and the email address associated with your account. We'll respond within 30 days and forward your request to Stripe so Stripe can destroy the underlying biometric identifier they hold.
Release and consent
This page is the written notice required by the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington HB 1493, and the biometric-processing provisions of the Colorado Privacy Act. Reaching this page and subsequently proceeding through the affirmative-consent checkbox on /verification/start constitutes your written release under BIPA §15(b)(3) and the corresponding provisions of the other statutes named above, given electronically under the federal E-SIGN Act (15 U.S.C. §7001) and state analogs. We record the version of this notice you saw (currently “2026-07-25”), the timestamp, and the IP/user-agent context in a BiometricConsentReceipt row so we can prove which version you consented to.
Contact
Questions, corrections, or deletion requests: privacy@fulluproar.com.