What this covers
This policy applies to biometric identifiers and biometric information collected through EarnX's identity verification step. It sits alongside our Privacy Policy, and where the two differ on biometric data, this page governs.
Not every user is asked to verify. Verification is triggered when our fraud checks flag an account, or when a withdrawal looks unusual. Most users will never see it.
What we collect
- A short video and one or more images of your face, captured live by your device camera.
- A scan of your facial geometry, meaning a mathematical representation of the distances and relationships between facial landmarks. This is stored in encrypted form and cannot be turned back into a photograph of you.
- Liveness data, meaning measurements of how your face moved during the scan, which is how a real person is told apart from a photograph, a mask or a video replay.
We do not collect fingerprints, voiceprints, iris or retina scans, or DNA. We do not ask for a passport, driving licence or other identity document, and there is no way to upload one to us.
Why we collect it
The purpose is narrow and it is the only purpose:
- to confirm that a real, live person is behind the account, rather than a bot or a recorded image;
- to confirm that the same person is not operating several accounts, which is the main way this kind of platform is defrauded; and
- to release a withdrawal that our automated checks have held, or to restore access to an account that has been restricted.
Fraud on a rewards platform is not victimless. Every reversed completion is money our partners take back, and the cost lands on the users who did the work honestly. This check exists to protect them.
Consent, and your right to refuse
We do not capture anything until you have read a notice and actively agreed. Before the scan starts you are shown, on one screen: what is collected, the specific purpose, how long it is kept, and who receives it. You then have to tick a box. We record that you did, when, and from what address.
You can withdraw your consent at any time by emailing contact@earnx.gg. We will ask our provider to delete the biometric data they hold for you. Withdrawing consent does not undo processing that already happened, and if you withdraw it we may need to verify a future withdrawal by manual review instead.
Who holds it
The scan is captured and held by our verification provider, Verisoul Inc., 1401 Lavaca Street, Suite 989, Austin, Texas 78701, United States. Verisoul acts as an independent controller of biometric data, meaning they determine how it is processed for verification purposes and are directly responsible for it.
TigerTree Solutions Ltd stores only a reference to the verification session and whether it passed. We can ask Verisoul to show us the capture again while a review is open, and access to that screen is restricted to our most senior administrator role.
Biometric data is processed and stored in the United States. If you are in the UK or the EEA, that transfer relies on the safeguards described at International transfers.
Retention and destruction schedule
This is the schedule required by Illinois, Texas and Colorado law.
- Face images and video. Destroyed once the verification decision has been made and any review or dispute connected to it is closed.
- Facial geometry scan and liveness data. Destroyed at the earlier of two points: when the purpose for collecting it has been satisfied, or three years after your last interaction with the verification provider. Whichever comes first, without exception.
- Our own records. We keep the session reference and the pass or fail outcome for as long as your account is open, and then in line with the retention periods in our Privacy Policy. These are not biometric data: they are a reference number and a yes or no.
- Shorter periods win. Where the law that applies to you requires destruction sooner, that shorter period applies instead. Texas requires destruction within a reasonable time and no later than one year after the purpose ends, and we apply that to Texas residents.
- On account closure. If you close your account we ask our provider to destroy your biometric data rather than waiting out the three-year limit.
Destruction means permanent deletion of the images, the video and the encrypted template. It is not archiving and it is not anonymisation.
What we never do
- We never sell, lease, trade or otherwise profit from biometric data.
- We never use it for advertising, for building a profile of you, or for training any model.
- We never disclose it to anyone else, except to the verification provider who performs the check, or where we are required to by a warrant, a court order or another legal obligation.
- We never use it to identify you outside EarnX, and we never share it with our offer or survey partners.
How it is protected
The scan is encrypted on your device before it is transmitted, and again in transit. It is stored encrypted. We apply the same standard of care to biometric data that we apply to the most sensitive information we hold, and at least the standard of care our industry applies to confidential information.
If a security incident ever affects biometric data, we will notify the people affected and the relevant authorities within the deadlines the law sets, and we maintain a written response procedure for exactly that.
Your rights
- Refuse the scan and use manual review instead.
- Withdraw your consent at any time.
- Ask what biometric data is held about you.
- Ask for it to be deleted.
- Ask a person to review any decision that was made about your account.
- Complain to us, and then to a regulator.
Email contact@earnx.gg from your account address, with Biometric in the subject line.
State and country specific rights
- Illinois. Under the Biometric Information Privacy Act (740 ILCS 14), we give you written notice that biometric identifiers and biometric information are being collected and stored, the specific purpose set out above, and the retention term set out above, and we obtain your written release before collection. This page is our publicly available written retention and destruction policy.
- Texas. Under the Capture or Use of Biometric Identifier Act, we obtain your informed consent before capture, we do not sell or disclose your biometric identifier except as permitted, and we destroy it within a reasonable time and no later than one year after the purpose ends.
- Colorado. We maintain this written policy with a retention schedule, a protocol for responding to a security incident, and deletion guidelines, and we obtain separate consent before collection rather than bundling it with anything else.
- Washington and other states. We obtain consent before enrolling a biometric identifier in a database for a commercial purpose, and we do not sell or lease it.
- California. Biometric information is sensitive personal information. We use it only to verify identity and prevent fraud, and never to infer characteristics about you. It is never sold or shared.
- UK and EEA. A facial scan used to identify you uniquely is special category data under Article 9 of the UK and EU GDPR. We rely on your explicit consent under Article 9(2)(a), which is why the separate tick and the manual review alternative both exist.
Contact
- Email contact@earnx.gg
- Post: TigerTree Solutions Ltd, Unit A 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE

