Biometric data policy

Last updated: 15 August 2026

The short version. To place your head correctly in a passport photo, our software has to find your eyes and measure how tall your head is in the frame. Those measurements exist for a few seconds while your photo is being processed and are then gone. We never build a faceprint, we never try to work out who you are, we never match you against any database, and we never sell, lease, trade or otherwise profit from anything we measure.

This policy is published under section 15(a) of the Illinois Biometric Information Privacy Act (740 ILCS 14) and is written to also satisfy the notice duties in the Texas Capture or Use of Biometric Identifier Act, Colorado HB 24-1130 and Washington RCW 19.375. It applies to everyone, wherever you live.

1. What we measure

When you upload a photo, our software locates a small number of points on your face and derives measurements from them:

  • The centre of each eye, the tip of your nose and the corners of your mouth, used to find the face and to straighten a tilted photo.
  • Eye corners, brow and eyelid positions, used to check that your eyes are open and your expression is neutral, and to detect glasses.
  • The top of your head and the point of your chin, used to compute head height as a proportion of the frame.

Under Illinois law a scan of face geometry counts as a biometric identifier, and measurements of the kind above may be treated as one whether or not anybody is trying to identify you. We therefore treat them as biometric data and apply this policy to them, without conceding that any particular measurement is a biometric identifier in law.

2. Why we measure it

For one purpose only: to produce a photo that meets the U.S. Department of State requirements for a passport photo, and to tell you when your photo cannot meet them. The head must fill between 1 inch and 1 3/8 inches of a 2 by 2 inch print, your eyes must sit between 1 1/8 and 1 3/8 inches from the bottom, your expression must be neutral and your eyes open. There is no way to check those rules without measuring your face.

3. What we never do

  • We do not perform facial recognition. Nothing in our software compares your face to any other face, to any watchlist, or to any database.
  • We do not create or store a face template, faceprint, embedding or vector that could be used to recognise you in a different photo.
  • We do not use your photo or any measurement from it to train artificial intelligence or any other model. The models we run are open-source and pre-trained, and they run offline on our own server.
  • We do not sell, lease, trade or otherwise profit from your biometric data. Illinois law forbids this outright and we would not do it in any case.
  • We do not disclose your biometric data to anyone. See section 6.

4. Retention schedule

This is the schedule required by section 15(a) of the Illinois Act.

  • Facial measurements: not retained. They are computed in the memory of the processing server, used for the checks, and discarded when processing ends, normally within seconds. They are never written to disk and never stored in your order record.
  • The photo you uploaded: 7 days. Deleted automatically 7 days after upload, whether or not you bought anything.
  • The finished photo you bought: 30 days. Kept so you can download it again, then deleted automatically.
  • Outer limit. Regardless of the above, we permanently destroy all biometric data when the purpose for collecting it has been satisfied, or within three years of your last interaction with us, whichever comes first. In practice the periods above are far shorter, and the three-year limit never becomes relevant.
  • Texas. Where the one-year rule in Texas Business and Commerce Code § 503.001 applies, our periods above are shorter than it requires and we meet it by a wide margin.

A refund shortens retention rather than extending it: refunding an order revokes the download and drops the file into the deletion sweep.

5. How we destroy it

Destruction is automatic and does not depend on anyone remembering to do it. A scheduled sweep on our server checks the age of every stored file against the periods in section 4 and deletes anything past its date. Deletion removes the file from the server's storage. Backups, where they exist, roll forward on a shorter cycle than the retention periods above, so a deleted photo does not survive in one.

If you would like your photo deleted sooner, email us and we will delete it and confirm when it is done.

6. Disclosure

We do not disclose, redisclose or otherwise disseminate your biometric data. No processor of ours receives it, because it never leaves the memory of the machine that computes it.

If you order prints, our print partner receives the finished photograph, your name and your delivery address, so they can print and post your order. A finished passport photograph is an ordinary photograph. It carries no measurements and no template.

We would disclose biometric data only if we were required to by a valid subpoena or court order, or if you asked us to in writing. Neither has happened.

7. How we protect it

We store and transmit your data using at least the standard of care we apply to our own confidential information, and no less than the reasonable standard of care in our industry. Traffic to and from the site and the processing server is encrypted in transit. The processing server is operated by Hetzner Online GmbH in Germany, access to it is restricted to the operator, and it runs no external image APIs, so your photo is not passed to a third-party service for analysis.

8. Your consent

Before your photo is processed, we tell you what we are about to measure, why, and how long we keep it, and we ask you to agree. That notice and your agreement are the written notice and written release required by section 15(b) of the Illinois Act. You can withdraw your agreement at any time by emailing us, and we will delete anything we still hold.

If you do not agree, we cannot produce your photo, because there is no way to check a passport photo against the rules without measuring the face in it.

9. Children

Passport photos are often taken of babies and children. Where the photo is of a child, the parent or legal guardian gives the agreement described in section 8 on the child's behalf, and everything in this policy applies to the child's data in the same way. We do not knowingly let a child under 13 contract with us directly.

10. State-specific notes

  • Illinois. This document is our written policy under 740 ILCS 14/15(a). The notice and release under 15(b) are given at the point of upload.
  • Texas. We inform you before capture and obtain your consent, we do not sell or profit from biometric identifiers, and we destroy them well inside the statutory period.
  • Colorado. Sections 1, 2, 4 and 6 give the notice required by HB 24-1130 covering what we collect, why, how long we keep it and who receives it. We do not use biometric data to profile you and we do not condition any unrelated service on your consent.
  • Washington. We do not enrol biometric identifiers in a database for a commercial purpose, which is the conduct RCW 19.375 regulates.
  • California. Biometric information is sensitive personal information under the CCPA. We use it only to deliver the service you asked for, which is a use for which no right to limit applies, and we do not sell or share it.

11. Questions and complaints

Email help@onepassphoto.com. A person reads it. If you want your data deleted, say so and we will do it and write back to confirm.

Changes to this policy are published on this page with a new date at the top. If a change affects what we measure or how long we keep it, we will say so plainly rather than quietly editing the text.