EarnX

Biometric Data Policy

Last updated 3 September 2026Version 2026-09-03

EarnX asks some users to complete a face scan before a withdrawal is released. A face scan is biometric data, and the law rightly treats it differently from everything else we hold. This page is the written policy that Illinois, Texas and Colorado require us to publish: what is collected, why, who holds it, exactly how long, and how it is destroyed.

What this covers

This policy applies to biometric identifiers and biometric information collected through EarnX's identity verification step. It sits alongside our Privacy Policy, and where the two differ on biometric data, this page governs.

Not every user is asked to verify. Verification is triggered when our fraud checks flag an account, or when a withdrawal looks unusual. Most users will never see it.

What we collect

  • A short video and one or more images of your face, captured live by your device camera.
  • A scan of your facial geometry, meaning a mathematical representation of the distances and relationships between facial landmarks. This is stored in encrypted form and cannot be turned back into a photograph of you.
  • Liveness data, meaning measurements of how your face moved during the scan, which is how a real person is told apart from a photograph, a mask or a video replay.

We do not collect fingerprints, voiceprints, iris or retina scans, or DNA. We do not ask for a passport, driving licence or other identity document, and there is no way to upload one to us.

Why we collect it

The purpose is narrow and it is the only purpose:

  1. to confirm that a real, live person is behind the account, rather than a bot or a recorded image;
  2. to confirm that the same person is not operating several accounts, which is the main way this kind of platform is defrauded; and
  3. to release a withdrawal that our automated checks have held, or to restore access to an account that has been restricted.

Fraud on a rewards platform is not victimless. Every reversed completion is money our partners take back, and the cost lands on the users who did the work honestly. This check exists to protect them.

Who holds it

The scan is captured and held by our verification provider, Verisoul Inc., 1401 Lavaca Street, Suite 989, Austin, Texas 78701, United States. Verisoul acts as an independent controller of biometric data, meaning they determine how it is processed for verification purposes and are directly responsible for it.

TigerTree Solutions Ltd stores only a reference to the verification session and whether it passed. We can ask Verisoul to show us the capture again while a review is open, and access to that screen is restricted to our most senior administrator role.

Biometric data is processed and stored in the United States. If you are in the UK or the EEA, that transfer relies on the safeguards described at International transfers.

Retention and destruction schedule

This is the schedule required by Illinois, Texas and Colorado law.

  • Face images and video. Destroyed once the verification decision has been made and any review or dispute connected to it is closed.
  • Facial geometry scan and liveness data. Destroyed at the earlier of two points: when the purpose for collecting it has been satisfied, or three years after your last interaction with the verification provider. Whichever comes first, without exception.
  • Our own records. We keep the session reference and the pass or fail outcome for as long as your account is open, and then in line with the retention periods in our Privacy Policy. These are not biometric data: they are a reference number and a yes or no.
  • Shorter periods win. Where the law that applies to you requires destruction sooner, that shorter period applies instead. Texas requires destruction within a reasonable time and no later than one year after the purpose ends, and we apply that to Texas residents.
  • On account closure. If you close your account we ask our provider to destroy your biometric data rather than waiting out the three-year limit.

Destruction means permanent deletion of the images, the video and the encrypted template. It is not archiving and it is not anonymisation.

What we never do

  • We never sell, lease, trade or otherwise profit from biometric data.
  • We never use it for advertising, for building a profile of you, or for training any model.
  • We never disclose it to anyone else, except to the verification provider who performs the check, or where we are required to by a warrant, a court order or another legal obligation.
  • We never use it to identify you outside EarnX, and we never share it with our offer or survey partners.

How it is protected

The scan is encrypted on your device before it is transmitted, and again in transit. It is stored encrypted. We apply the same standard of care to biometric data that we apply to the most sensitive information we hold, and at least the standard of care our industry applies to confidential information.

If a security incident ever affects biometric data, we will notify the people affected and the relevant authorities within the deadlines the law sets, and we maintain a written response procedure for exactly that.

Your rights

  • Refuse the scan and use manual review instead.
  • Withdraw your consent at any time.
  • Ask what biometric data is held about you.
  • Ask for it to be deleted.
  • Ask a person to review any decision that was made about your account.
  • Complain to us, and then to a regulator.

Email contact@earnx.gg from your account address, with Biometric in the subject line.

State and country specific rights

  • Illinois. Under the Biometric Information Privacy Act (740 ILCS 14), we give you written notice that biometric identifiers and biometric information are being collected and stored, the specific purpose set out above, and the retention term set out above, and we obtain your written release before collection. This page is our publicly available written retention and destruction policy.
  • Texas. Under the Capture or Use of Biometric Identifier Act, we obtain your informed consent before capture, we do not sell or disclose your biometric identifier except as permitted, and we destroy it within a reasonable time and no later than one year after the purpose ends.
  • Colorado. We maintain this written policy with a retention schedule, a protocol for responding to a security incident, and deletion guidelines, and we obtain separate consent before collection rather than bundling it with anything else.
  • Washington and other states. We obtain consent before enrolling a biometric identifier in a database for a commercial purpose, and we do not sell or lease it.
  • California. Biometric information is sensitive personal information. We use it only to verify identity and prevent fraud, and never to infer characteristics about you. It is never sold or shared.
  • UK and EEA. A facial scan used to identify you uniquely is special category data under Article 9 of the UK and EU GDPR. We rely on your explicit consent under Article 9(2)(a), which is why the separate tick and the manual review alternative both exist.

Contact

  • Email contact@earnx.gg
  • Post: TigerTree Solutions Ltd, Unit A 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE

Earn