Help · biometric processing
Biometric data, plainly: what we keep, what we delete.
This FAQ and its retention schedule cover the event-page one-time selfie-search mode only. Other biometric modes have separate consent disclosures and controls. Where event, account, consent, age, and jurisdiction gates allow it, PodiumBase can use AWS Rekognition to return likely eligible race-photo matches. Matching can miss photos or return false matches. This page explains what that one-time mode processes, how long it keeps data, and your rights. We clarified this scope on August 2, 2026.
Biometric processing FAQ
- What biometric data does PodiumBase process?
- This FAQ covers event-page one-time search only. Where event, account, consent, age, and jurisdiction gates allow it, PodiumBase computes a face embedding — a mathematical representation of facial geometry — and compares it with eligible photos from that event to return likely matches. Matching can miss photos or return false matches. PodiumBase does not sell or rent biometric data or share embeddings outside AWS Rekognition, our sub-processor under a written data-processing agreement.
- How long does PodiumBase retain biometric data?
- Face embeddings are stored in a per-event AWS Rekognition Collection and are permanently deleted when the event closes, on explicit race-director purge, or within 60 days of the event date — whichever occurs first. Raw selfie images uploaded by athletes are permanently deleted within 60 seconds of matching; only matched-photo IDs are returned. In all cases, no biometric data is retained beyond 3 years from the data subject’s last interaction with the service.
- Which state biometric laws apply to PodiumBase?
- For V1, event-page one-time selfie search is gated for visitors located in Illinois pending external-counsel review against current BIPA case law. Illinois athletes can still find their race photos by bib-number search. For this event-page mode, eligible Texas and Washington residents see the normal flow under its event, account, consent, age, and jurisdiction gates. Cross-event search and enrollment retain their own disclosures and gates. EU/UK residents retain GDPR rights independent of this event-page flow.
- How do I opt out or delete my biometric data?
- You can opt out of biometric processing at any time in your athlete settings. To delete face data PodiumBase has already processed, email privacy@podiumbase.io or use the data-deletion request flow in your account. Race directors can purge an entire event’s Rekognition Collection from event settings.
- How is my consent recorded?
- The event-page selfie-search modal records the signed disclosure version and policy hash submitted with that consent. Those fields identify the consent disclosure; they do not claim to reproduce this separate FAQ block from the audit row alone. The public event-page retention block on this page has its own version (FAQ_BIOMETRIC_RETENTION_BLOCK_VERSION) and is maintained with the counsel-reviewed policy source.
- Who can I contact about biometric data at PodiumBase?
- Email privacy@podiumbase.io for privacy questions or to exercise a data right. For the full data-handling account, see the PodiumBase Privacy Policy at /legal/privacy.
What we process
For an event-page one-time search, where event, account, consent, age, and jurisdiction gates allow it, we compute a face embedding (a mathematical representation of facial geometry) and compare it with eligible photos from that event to return likely matches. Matching can miss photos or return false matches. The embeddings are biometric identifiers under U.S. state laws including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington’s RCW 19.375.
Event-page one-time search uses that event’s AWS Rekognition Collection. This schedule does not describe cross-event search or opt-in enrollment; those modes present their own consent disclosures and controls before use. We do not sell or rent biometric data. We do not share embeddings with third parties beyond AWS Rekognition (our sub-processor, under a written data-processing agreement).
Retention schedule for biometric data
- Face embeddings (mathematical representations) are stored in a per-event AWS Rekognition Collection.
- Embeddings are permanently deleted when the event closes, OR upon explicit race director purge action, OR within 60 days of the event date, whichever occurs first.
- Raw selfie images uploaded by athletes are permanently deleted within 60 seconds of matching. Only matched-photo IDs are returned.
- In all cases, no biometric data is retained beyond 3 years from the data subject’s last interaction with the service.
State biometric laws
For our V1 launch, event-page one-time selfie search is gated for visitors located in Illinois. Illinois athletes can still find their race photos by searching their bib number; the event-page face-matching upload option is hidden in that state pending external counsel review of our consent flow against the latest BIPA case law. For this mode, eligible Texas and Washington residents see the normal flow under event, account, consent, age, and jurisdiction gates. Cross-event search and enrollment retain separate disclosures and gates.
Your rights
You can opt out of biometric processing at any time in your athlete settings. If you want us to delete face data we’ve already processed for you, email privacy@podiumbase.io or use the data-deletion request flow in your account.
Race directors can purge an entire event’s Rekognition Collection from event settings. EU/UK residents retain GDPR rights (access, erasure, portability, objection to processing) independent of our default flow.
Contact
For privacy questions or to exercise a data right, email privacy@podiumbase.io. For a full account of how we handle data, see our Privacy Policy.