BIOMETRIC IDENTIFIER AND INFORMATION POLICY
FreeRoyalties, Inc. (d/b/a Zooly) (hereafter “Company”) maintains the following policy regarding end user biometric data that Company collects, captures, receives through trade, otherwise obtains, possesses, stores, discloses, and/or uses.
Biometric Data Defined
As used in this policy, biometric data includes “biometric identifiers” and “biometric information” as defined in the Illinois Biometric Information Privacy Act, 740 ILCS §14/1, et seq. “Biometric identifier” means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color or eye color. “Biometric information” means any information, regardless of how it is captured, converted, stored or shared, based on an individual’s biometric identifier used to identify an individual.
Collection, Capturing, Storage and Use of Biometric Data
Company, and/or its vendors may collect, capture, receive through trade, otherwise obtain, store, and/or use an end user’s biometric data. Further, Company may utilize customer’s (or end user’s) mobile phone facial recognition software as an alternative to end user entering a password in order to access company applications (including, without limitation, email systems) on end users’ personal mobile phones.
The biometric data is collected, captured, received through trade, otherwise obtained, stored and/or used for the purpose of facilitating password-protected access to company applications on end users’ personal mobile phones. For the avoidance of doubt, Company does not collect, possess, or retain biometric data utilized by end users’ mobile phones for facial-recognition-based access to company applications.
Disclosure of Biometric Data
Company will not disclose, redisclose or otherwise disseminate an end user’s biometric data unless: (i) the end user consents to such disclosure; (ii) the disclosure or redisclosure completes a financial transaction requested or authorized by the end user; (iii) the disclosure or redisclosure is required by State or federal law or municipal ordinance; or (iv) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
Retention and Destruction of Biometric Data
To the extent it collects or possesses biometric data, Company shall retain end user biometric data only one year from the date of the end users last interaction with Company. At such time Company shall permanently destroy such data.
Data Storage, Transmission and Protection
To the extent it collects or possesses biometric data, Company will store, transmit and protect biometric data using a reasonable standard of care. Such storage, transmission and protection from disclosure will be performed in a manner that is the same as or more protective than the manner in which Company stores, transmits and protects from disclosure other confidential and sensitive information, including personal information that can be used to uniquely identify an individual or an individual’s account or property, such as account numbers, PINs, driver’s license numbers and social security numbers.
BIOMETRIC IDENTIFIER AND INFORMATION AUTHORIZATION AND RELEASE
I acknowledge that I have received a copy of FreeRoyalties, Inc. (“Company”) Biometric Identifier and Information Policy (“BIPA Policy”) and Biometric Identifier and Information Disclosure (“BIPA Disclosure”), and understand that Company and/or its vendors may collect, capture, receive through trade, otherwise obtain, store and/or use my biometric identifiers (such as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry) and biometric information (which is information, regardless of how it is captured, converted, stored or shared, based on an individual’s biometric identifier used to identify an individual). I further acknowledge and understand that Company makes available to me the option of using my mobile phone’s facial recognition software to facilitate password-protected access to company applications on my personal mobile phone. I further understand that Company does not collect, possess, or retain biometric data utilized by my mobile phone for facial-recognition-based access to company applications.
As a condition of my use of Company’s photobomb experience, I hereby:
(1) authorize Company and its vendors to collect, capture, receive through trade, otherwise obtain, store, and/or use my biometric identifiers and biometric information;
(2) authorize the use of facial recognition software on my mobile device to facilitate the photobomb experience;
(3) release and hold harmless Company from any liability that might result from the collection, capturing, receiving through trade, otherwise obtaining, storage, use, and/or destruction of my biometric identifiers and/or biometric information, provided such collection, capturing, receiving through trade, otherwise obtaining, storage, use and destruction is for purposes relating to the purposes described in the BIPA Policy.