Biometric Information Retention & Destruction Schedule

Effective Date: August 3, 2026 Last Updated: August 4, 2026

This document is OnRoady's publicly available written policy governing the collection, storage, use, and destruction of biometric identifiers and biometric information (together, "biometric data"), as required by the Illinois Biometric Information Privacy Act (740 ILCS 14, "BIPA"), the Texas Capture or Use of Biometric Identifier Act ("CUBI," Tex. Bus. & Com. Code §§ 503.001 et seq.), and the Washington Biometric Identifiers Act ("WBITA," RCW 19.375).

It is issued by OnRoady LLC, a California limited liability company.


1. What we collect

OnRoady processes biometric identifiers in two distinct pipelines. Both are disclosed here.

1.1 Bystander-blurring pipeline (video uploads)

When you upload dashcam or witness video footage through OnRoady, our automated blurring pipeline processes the video to detect and obscure:

Faces belonging to the uploading driver and to bystanders are treated identically. We do not maintain a face database, do not match faces across videos, and do not identify individuals from their biometric data. The blurring pipeline is a privacy control, not an identity system. This pipeline runs on our infrastructure using OpenCV and does not transmit biometric data to third parties.

1.2 Identity-verification pipeline (driver KYC)

When you upload a driver's-license photo and a selfie to enable payouts, we run a one-time comparison to confirm the person in the selfie is the person on the license. This uses:

AWS Rekognition receives the two image bytes over TLS, returns a similarity score and attribute set, and does not store the images against your identity (it holds them transiently for the duration of the API call). We record only the numeric outcome (match / no-match, attribute presence). The raw facial-geometry vectors are not persisted on our side or theirs beyond the API request lifetime.

We do not use identity-verification biometrics to match faces across videos, across accounts, or against any external database. Rekognition is used for a single 1:1 comparison — your selfie against your own license — and nothing else.


2. Purpose

Biometric processing on OnRoady has two, and only two, purposes:

We do not use biometric data for:


3. Consent

By accepting our Terms of Service and uploading footage, you provide informed, written consent (through the electronic-acceptance mechanism authorized by 15 ILCS 1/1 et seq., the Illinois Electronic Commerce Security Act) to the collection, storage, and use of biometric data as described in this schedule.

If you reside in Illinois, Texas, or Washington, you will additionally see a one-tap consent screen before your first upload confirming this schedule. You may withdraw consent at any time by emailing privacy@onroady.app; withdrawal takes effect for future uploads only and does not affect processing already lawfully completed.


4. Retention Schedule

Bystander-blurring pipeline (§1.1):

Data category Retention limit
Facial-geometry vectors (in-video) Processed in memory during the blurring pipeline and destroyed within twenty-four (24) hours of the pipeline finishing, regardless of upload disposition.
Plate-detection vectors Same as above.
Blurred output video Retained according to the video-retention schedule in the Privacy Policy (§6). The blurred output does not contain biometric identifiers.
Source (unblurred) video Retained only as long as required to complete blurring and any dispute review; destroyed within thirty (30) days of bounty resolution.

Identity-verification pipeline (§1.2):

Data category Retention limit
Facial-geometry vectors (selfie / license face) Held transiently by AWS Rekognition for the duration of a single API call and not persisted; not stored on OnRoady systems.
Match / no-match outcome Retained on the user record as identity_status while the user's account is active. Deleted when the account is deleted.
Selfie image + license image Retained on Cloudflare R2 while the user's account is active for dispute review and re-verification. Deleted within thirty (30) days of account deletion.

In no event is biometric data retained longer than the earlier of: (a) three (3) years from the date of last collection, or (b) the date the initial purpose for collection has been satisfied — as required by 740 ILCS 14/15(a).


5. Destruction

When a retention limit is reached, biometric data is deleted from active storage, and the corresponding database records are set to a hashed-null sentinel. Backups containing biometric data are rotated within ninety (90) days.


6. Disclosure

We do not disclose, redisclose, sell, lease, trade, or otherwise profit from biometric data. Disclosure occurs only if:


7. Security

Biometric data is stored using AES-256 encryption at rest and TLS 1.2+ in transit. Access is restricted by row-level security to the automated blurring and identity-verification services; no OnRoady employee has direct read access to raw biometric vectors. Access logs are retained for two (2) years and reviewed periodically.

Selfie and license images used by the identity-verification pipeline (§1.2) are stored on Cloudflare R2 with keys accessible only via short-lived (≤1 hour) presigned URLs; direct-URL access is denied. AWS Rekognition is invoked from our backend over TLS 1.2+ with request signatures scoped to the CompareFaces / DetectFaces API surface only.


8. Rights

If you are a resident of Illinois, Texas, Washington, or any other jurisdiction that grants biometric-privacy rights, you may:

Requests may be submitted in-app at Settings → Privacy or by email to privacy@onroady.app. We respond within thirty (30) calendar days.


9. Contact

Questions about this policy or requests concerning biometric data:

Email: privacy@onroady.app Mailing Address: OnRoady LLC, 101 E. San Fernando St Suite 138, San Jose, CA 95112