Test environment. Payments here run in test mode and no real money is taken. Nothing bought here is reviewed or delivered for real, and uploaded photos are deleted within 30 days at the latest. There is no live version of this service yet, and the support mailbox is not monitored.

Privacy policy

Last updated 16 September 2026

Draft, pending legal review

No lawyer has read this page. It was written by the people building IDPhoto.now, from the code and the design documents, and it is published in draft so that you can see what we do before you decide whether to use us. It is not legal advice, and the sections marked as open questions are genuinely open.

You are about to hand a stranger a photograph of your face so you can apply for a government document. That is a serious thing to ask for, and a leak is not a password you can change. This page says exactly what we take, why, who else touches it, how long it stays and what we have decided never to do with it.

Who is responsible for your photograph

IDPhoto.now is the controller for everything you upload and for the order record attached to it. The photograph is ours to look after, and we do not pass that responsibility to anyone else. Our payment provider, Dodo Payments, is a separate controller for the payment data it handles — see who processes your data.

What we collect, and why

WhatWhy we have it
The photograph you uploadTo run the automated checks, to let a trained reviewer look at it, and to give you the files you paid for. There is no other reason we hold it.
Measurements taken from that photographWidth and height, file format, byte length, a SHA-256 hash, exposure, sharpness, background uniformity and background colour. These are the numbers in your report, and they are the evidence if you later dispute what we told you.
A few EXIF fieldsCamera make and model, the name of any software that wrote the file, the capture date, and the orientation flag. We use them to check the photo is recent and to notice editing software. We also record a single true or false for whether a GPS block exists in the file — we never read, store or display the coordinates themselves.
An email address, given at the payment stepFor the receipt, for the message telling you your photo has been reviewed, and for support. You do not give us an email address to check a photo — only to buy one.
The order recordYour order reference, the document profile you chose, the price at the moment you started, payment and review states, timestamps, and the provider identifiers for any payment, refund or dispute. Accounting and complaint handling run on this, not on the photograph.
An audit trailWho did what to which order and when: the upload, the check, the payment decision, a reviewer opening the file, a download, a deletion. It is how we can answer "who looked at my photo" with something better than a shrug.
One cookieA random token named idp_guest, which is what connects this browser to your order. See cookies below.

The browser detail we keep, and the one we do not

Against a browser session we may store a coarse browser family, for investigating abuse. It is not a user-agent string and not a fingerprint. It is one of exactly four words: mobile, desktop, automated or unknown.

We do not put IP addresses in our session rows or in our audit trail. That is a deliberate design decision, written into the data model rather than into a promise. Our hosting and platform providers keep their own request logs, which contain IP addresses on their own retention schedules — those are theirs, not ours, and we will not describe them as if we controlled them.

On what basis we process it

For the photograph, the measurements and the order record: performing the contract you entered into when you asked us to check a photo, and taking steps at your request before that contract. For the audit trail and the fraud and abuse controls: our legitimate interest in running a service that can account for who touched a customer's face photograph. For the accounting record: our legal obligations.

Two honest qualifications. First, the lawful-basis analysis is one of the things the pending legal review has to settle; we have set it out as we understand it rather than leaving the section blank. Second, a facial photograph becomes biometric data under Article 9 of the GDPR when it is processed for the purpose of uniquely identifying a person. Our design deliberately avoids that purpose — we measure image properties, we build no templates, and there is no face detector in the service at all today. We do not have a legal opinion confirming that analysis and we are not going to pretend we do.

Who processes your data

WhoRoleWhat they handle
CloudflareProcessor acting for usHosting and content delivery for the website, and the private object storage that holds the image files themselves.
ConvexProcessor acting for usThe application database: orders, check results, reviews, identities, audit rows. No image file is ever stored there.
Dodo PaymentsIndependent controller, and merchant of recordPayment and buyer data. Dodo is the legal seller on your receipt and on your bank statement — not us — and it collects and remits sales tax, VAT and GST. Under its own data processing agreement it acts as an independent controller for payment data, not as our processor.
An email providerProcessor acting for us, when one existsTransactional email. We have not selected one yet. Until we do, no automated email is being sent by this service, and we will name the provider here before it sends anything.

Two consequences of that table are worth saying out loud, because the marketing language around merchants of record routinely blurs them.

  • Dodo never receives your photograph. Files are delivered only from our own authenticated storage, never through a payment provider's fulfilment channel.
  • Dodo being the merchant of record removes none of our obligations to you. It handles transaction taxes and it is the seller of record. Every data-protection duty for your photograph, and the accuracy of everything we say about what the product does, stays with us.

Cookies and analytics

One cookie: idp_guest. It is a random token, marked HttpOnly, with SameSite=Lax and a thirty-day lifetime, and only the hash of it is stored on our side. It holds no personal data — it exists so that the browser that created an order can come back to it. It is strictly necessary for the service to work at all, which is why there is no banner asking you to accept it.

There are no analytics cookies, no advertising pixels and no third-party tags on any page that shows a photograph or an order. We have not selected an analytics vendor, and no vendor is permitted on those pages if we ever do.

How long we keep things

  • Images for an order that was never paid for: 24 hours.
  • Images for a paid order: 30 days, so you can come back for the file.
  • Earlier than either, whenever you ask. There is a delete button on your own order page. See delete your photos and data.

Both of those windows are product decisions taken pending legal review, and they may change once the consumer-law and accounting positions are settled. They are not legal conclusions.

The order record outlives the photograph, on purpose

When images are deleted, the order row survives with a flag recording that its materials are gone. So do the payment events, the refund records and the audit trail. None of them contains a photograph. We keep them because accounting and complaint handling need a record of what was sold and what happened — and because doing it this way means those needs never become a reason to hold on to your face.

One thing we are not going to hide: today the measurements taken from your photograph survive deletion of the image, and some of them are EXIF-derived strings such as a camera model and a capture date. Whether they ought to be purged with the image is an open question in our legal review. It is listed here rather than quietly left out.

Backups

Live data is deleted immediately. Our providers keep their own backups and snapshots on their own schedules, which we do not control and do not use to restore individual customer records. We will not claim instant erasure from every backup in the world, because that would not be true.

International transfers, and what "EU hosting" does not mean

Our providers are global platforms and processing can happen outside the country you are in. Dodo Payments' data processing agreement references the EU standard contractual clauses (2021/914) and the UK international data transfer addendum for its own transfers. Our own transfer mechanisms and the processing locations for each provider are not settled yet, and we are not going to write a sentence here that implies they are.

Two claims we specifically refuse to make:

  • Hosting in the EU is not, by itself, GDPR compliance. It is one input among many. Any site that presents an EU flag as a compliance statement is selling you a feeling.
  • A storage location hint is a hint, not a residency guarantee. Our object storage supports a location hint, which the provider describes as best effort. The only mechanism that guarantees where objects live is a jurisdictional restriction, fixed when the storage bucket is first created and never changeable afterwards. Unless and until this page says we have chosen one, we have not made you a residency promise.

What we never do

Each of these is something we could technically build and have decided not to. They are commitments, not aspirations.

  • We do not train models on customer photographs. Not ours, not anyone's.
  • We do not build a face-recognition database. There is no index anywhere in the system from a face to a person.
  • We do not create or retain biometric templates or face embeddings. There is no face detector in the service today at all; the face-related checks report not checked and a human measures them instead.
  • We do not infer sensitive characteristics from a photograph — not ethnicity, health, religion, age or gender. Nothing in the pipeline attempts it.
  • We do not sell, rent or share photographs with advertisers, data brokers or anyone outside the processors named above.
  • We never put photographs, image bytes, access tokens or full email addresses in logs or audit rows. Email addresses in audit rows are redacted to a form like a*****@example.com.
  • We do not reuse a photograph across orders. An uploaded file belongs to one order and one order only.
  • We do not look at photographs outside review and support, and every staff view is written to the audit trail with the name of the person who made it.
  • We do not edit photographs. No background replacement, no retouching, no face straightening, no generative upscaling. That is a product position as much as a privacy one, and it is explained on the standards we check against.
  • We never ask you to email us a photograph. See contact.

Location data in your own file

Because we hand back your original file unchanged, any metadata your camera wrote stays in it — including GPS coordinates, if your phone was recording them. We do not read those coordinates and we do not store them, but we also do not strip them, because stripping them would mean altering the file, and altering the file is the one thing this service exists not to do.

If that matters to you, turn location off for the camera app before you take the photo, or remove the location from the image on your phone before uploading. Offering an EXIF-stripped variant where a document profile permits it is on our list and is not built.

Children

Both document profiles we support today are for adults, and one of them — online passport renewal — is only open to applicants aged 25 or older under the State Department's own eligibility rules. We do not market to children. We do not collect a date of birth and we cannot verify anyone's age, so we do not design around an age check we do not have. Whether a separate notice is needed when we add a child profile is an open item for the legal review.

Your rights, and how to use them

Depending on where you live you have some or all of the following rights over your personal data: to get a copy of it, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable form, and to complain to your data protection authority. We do not make you jump through hoops to use any of them.

  • Erasure of your photographs is self-service and immediate. Open your order page and press the delete button. Delete your photos and data explains exactly what that removes and what it leaves behind.
  • Everything else goes to one address. Email us at support@idphoto.now with your order reference — it starts with ord_. Please do not attach the photograph.

We will ask you to show us that the request is yours, and we will do that with the least data we can get away with — normally by tying the request to an order you can already open. We will not ask you to send a scan of your passport or a photograph of yourself to prove who you are. If we genuinely cannot connect a request to an order, we will tell you so rather than delete someone else's data on a guess.

Security

The short version: image files live in private object storage with no public address at all; identifiers are long random values and knowing one authorises nothing on its own; access tokens are stored only as hashes; every private page is marked not to be cached or indexed; and links that we email are single use and expire in an hour. The long version, including the gaps we know about, is a working document rather than marketing copy, and this page will be updated as it changes.

What we cannot protect you from

It would be easy to stop at the section above. These are the limits, stated plainly: a compromised phone or browser, where the photograph is exposed before we ever receive it; someone with sustained control of your email inbox; anything you do with a file after you have downloaded it; a lawful order served on us or on one of our providers; and a serious compromise at a provider. We reduce the blast radius — private storage, unguessable keys, short retention — and we do not claim to have eliminated it.

Changes to this notice

When this page changes materially, the date at the top changes with it. When the legal review lands, the draft banner comes off and the open questions in this page get answers rather than being quietly deleted.

Related pages