SocureNewsletter_August2025_MicrositeHero (1)

Global Services Privacy Notice

Effective date: October 01, 2026

 

Welcome. This Global Services Privacy Notice (“Privacy Notice”) relates to Socure Inc. (collectively, “Socure,” “we,” “us,” or “our”), a platform providing digital identity verification and fraud prevention products and services (the “Services”), and describes How Socure Works, the Personal Information We Collect (and the Sources), Where We Store And Transfer Your Personal Information, How We Use Your Personal Information, How We Disclose Your Personal Information, How Long We Retain Your Personal Information, How We Protect Your Personal Information, our Lawful Bases for Processing, Your Data Rights, How to Exercise Your Data Rights, and How to Contact Us. 

This Privacy Notice applies when we verify your identity on behalf of businesses and business prospects (collectively our “Customers”) or on our own behalf, such as when deriving insights and network/graph-based risk intelligence, when verifying a Data Rights Request, and when you interact directly with Socure to verify your identity, including through document and biometric verification. Socure also maintains a separate Website Privacy Notice which includes our Cookie Policy, that applies when we market and sell our Services to you and when you visit and engage with us online, across our websites and digital content. If our Customers use our Services and you also engage with our marketing content, both notices may apply.

How Socure Works

Socure is a fraud, compliance and identity platform that helps Customers verify who someone is and catch fraud before it happens. When you try to open a bank account, verify a payment, or take another action with one of our Customers, that Customer may send us information about you so we can check things like:

  • Does this identity actually exist?
  • Have we seen this identity before? 
  • Does the identity belong to the person who provided it?
  • Is this a real person, an automated bot, or an AI agent?
  • What fraud risks are associated with the identity?

The Customer receives an output from us, which may be a score, a signal, or a recommendation, depending on the use case. The Customer then decides what to do with it. Socure doesn’t approve or deny your transaction; that decision belongs to the business you’re dealing with, unless we say otherwise for a specific product.

Most of the time, you won’t interact with Socure directly—we work behind the scenes for our Customers. The exceptions are DocV (document/selfie verification), Digital Intelligence (device and network risk signals), and Socure Pass (a reusable identity wallet your Customer pays for, but that you hold an account with). Your use of DocV is also subject to Socure’s DocV Terms of Use.

Some Customers also route their workflows through other companies using our RiskOS® platform. If they do, we may send your information to, or receive it from, those partners at the Customer’s direction. Those partner parties (“Customer-Enabled Partners”) handle your data under their own privacy terms and agreements with our Customer.

Two roles, one company. Because of how this works, Socure sometimes decides why and how your data is used (as a “Controller”), and sometimes processes your data on a Customer’s instructions (as a “Processor”). This matters because it determines who controls your data and who you’d contact about it:

When Socure is a Processor  When Socure is a Controller 
What this covers Verifying your identity or checking for fraud on behalf of a Customer — the vast majority of what we do Socure Pass accounts · DocV ·  creating and processing fraud-intelligence insights  · agent classification/trust assessment · verifying data rights requests
Who decides why/how your data is used The Customer Socure
Who to contact about this data The Customer who sent you to us Socure directly

 

A quick note on terms: “Controller” and “Processor” are the terms used under most privacy laws around the world, including most U.S. state privacy laws, and are used throughout this Privacy Notice as the global standard. If you live in California, your state’s privacy law, the California Consumer Privacy Act, uses different terms instead: “Business” and “Service Provider,” defined by what your contract with us says rather than by who decides how your data is used. We use Controller/Processor as shorthand throughout this Privacy Notice for clarity; where a specific law that is applicable to you, gives you different rights or imposes different obligations on us, we say so specifically.

When processing transactions for a Customer, Socure both acts as a Processor for a transaction, and may separately use some of that same data, as a Controller, to build fraud-detection insights across our customer base (for example, spotting a pattern of fraud across many companies). We do this insight building as a Controller, and it’s described further below.

Your Rights & Choices

Depending on where you reside, you may have the right to:

  • know: learn what personal information or categories of personal information we have about you;
  • access: request a copy of the personal information we have about you;
  • correct: correct inaccurate personal information we have about you;
  • delete: request that we erase personal information we have collected about you;
  • restrict processing: restrict our use of your personal information in certain limited circumstances;
  • opt out of / object to certain processing: object to certain processing of your personal information, such as targeted advertising or profiling in furtherance of decisions that produce a legal or similarly significant effect on you. 
    • Socure does not sell or share, and has not sold or shared in the preceding 12 months, any personal information (including biometric data or other personal information), as those terms are defined by applicable law. Socure also does not have actual knowledge that it sells or shares the personal information of consumers under 16 years of age, as defined by applicable law. Socure does not disclose sensitive personal information for purposes other than those specified in section 7027(m) of the California Consumer Privacy Act Regulations.
  • withdraw consent: withdraw your consent at any time, free of charge (any withdrawal applies only prospectively and does not affect processing already carried out based on your prior consent);

If you choose not to provide consent for biometric verification (e.g., during a DocV transaction), the transaction may be canceled, as we may be unable to complete the verification process. In such cases, please contact the Customer who initiated the transaction to discuss the alternative verification methods they provide.

  • data portability: receive your personal information in a portable, readily usable format, and, where required by applicable law, have it transmitted to another party;
  • appeal: appeal to us a refusal to take action on your request within a reasonable period after receiving our initial decision;
  • be free from discrimination: exercise any of these rights without being denied goods or services or otherwise discriminated against; and
  • lodge a complaint: file a complaint with your relevant data protection or supervisory authority.

If you’ve consented to any processing, you can withdraw that consent at any time. If you exercise these rights, you have the right not to be treated in a discriminatory way or receive a lesser degree of service from Socure. You also have the right to lodge a complaint with your applicable regulator.

How to exercise these rights depends on whether your request is about a specific transaction or about Socure’s own data:

  • If your request relates to a specific transaction — for example, an identity check performed when you opened an account with one of our Customers — please contact that Customer directly. In this situation, Socure is acting as a Processor, following the Customer’s instructions, and cannot act on that data without their direction.
  • For everything else — including Socure’s own fraud-intelligence insights, network/graph-based risk intelligence, inferred protected classification data used for bias and fairness testing, Socure Pass, employment, marketing, or vendor data — visit our Data Rights Form. In this situation, Socure is acting as a Controller. To help protect the security of your data, we will verify your identity before completing your request.

To exercise your data rights relating to a specific transaction or to our Customers’ use of the Services for automated decision-making, please submit your request to the Customer who sent you to us. When acting as a service provider to our Customers, we cannot take action on transaction-related personal information processed on their behalf without their written instructions. Where Socure processes personal information on behalf of a Customer, we may direct individuals to that Customer or otherwise act in accordance with the Customer’s instructions, consistent with applicable law and the Data Privacy Framework Principles.

There are situations where we may not be able to grant a request — for example, where the law requires us to keep a record, where granting it would undermine our fraud-prevention and security efforts, where it would infringe on someone else’s privacy, where the request is frivolous or unreasonable, or where the right simply isn’t available to you based on where you live.

We also recognize Universal Opt-Out Mechanisms, such as Global Privacy Control (GPC), as a valid way to opt out of the sale or sharing of your data, including for targeted advertising, where required by law.

You may designate an authorized agent to submit a request on your behalf, subject to verification. For questions, contact us at privacy@socure.com.

Personal Information We Collect

Socure collects personal information about you from Customers or prospects, from your device, from you, from companies that supply us with data to support verification (“Data Vendors”), and/or from companies we hire to help operate our Services, such as cloud hosting or biometric technology providers (“Third-Party Service Providers”). The chart below shows the categories of information Socure collects — whether to verify identities and prevent fraud on behalf of our Customers, to operate products like DocV and Socure Pass, or to generate our own verification results and risk insights — along with where that information comes from:

Categories of Personal Information Collected Sources of Information Collected
Identifiers, such as legal name, alias or nickname, mailing or physical address, email address, telephone number, social security number, passport, driver’s license or state identification card number, national identification number, credit file number (Canada), social insurance number (SIN-Canada), Pass or other government-issued identity document number, death records, wallet addresses, or other similar identifiers. Customers may provide this information to Socure in connection with a specific transaction.

You may provide this information to Socure in connection with a specific DocV or Socure Pass transaction.

Data Vendors may provide this information to Socure.
Financial Account and Transaction Information, including routing, account and credit card information, transaction history, details relating to your transactions with our Customers, including case management records, dispute and account histories, closure status, and data breach-related information. Customers may provide this information to Socure in connection with a specific transaction.

You may provide this information to Socure in connection with a specific DocV transaction.

Data Vendors may provide this information to Socure.
Identity Documents and Images, including selfies (which may include video captures) and government-issued or other identity documents, the information contained within those documents (e.g., date of birth), and metadata about the images such as the image EXIF, and time of image capture and/or upload. Customers may provide this information to Socure in connection with a specific DocV transaction.

You provide this information to Socure in connection with a specific DocV or Socure Pass transaction.
Additional Documents requested of you by Socure’s Customer for identity verification purposes, such as bank or utility statements. You provide this information to Socure in connection with a specific transaction with our Customer.
Biometric information, such as facial signatures (coordinates of corners of eyes and mouth, tip of nose or chin) and facial embeddings (vector representation of facial features) derived from the facial photographs on your government-issued identity document and/or selfie. You provide this information to Socure in connection with a specific DocV transaction, including when it is part of the Socure Pass experience.

Third-Party Service Providers used to extract biometric information from your photographs may provide this information to Socure.
Device, Browser, and Network Information, including Geolocation Data, such as Global Positioning System (GPS) coordinates, precise geolocation, Internet Protocol (IP) address, unique device identifier, device serial number, device type, device make and model, device operating system, mobile carrier, online identifier, SIM swap activity, language and time zone settings, referrer URL, and technical signals used to assess device and browser integrity. You and Your Device may automatically provide this information to Socure, if you have enabled such collection in your device settings, in connection with a specific transaction or when you interact with our Customers’ apps or websites.

Data Vendors may provide this information to Socure.
Behavioral data and inferences about how you typically interact with your device during a session, including session timing, which components of our and our Customers’ app or website you interact with, and how quickly you capture your photos or click submit. You and Your Device may automatically provide this information to Socure, if you have enabled such collection in your device settings, in connection with a specific DocV or Socure Pass transaction, or when you interact with our Customers’ apps or websites.
Characteristics of protected classifications, such as age, sex, apparent gender, immigration status, race, apparent skin color, and national origin. Customers may provide this information to Socure in connection with a specific transaction or to support fairness in outcomes and bias testing.

You provide this information to Socure in connection with a specific DocV transaction, including when it is part of the Socure Pass experience.

Socure may infer this information about you.
Verification Results and Risk Insights, such as derived insights (including insights across our consortium of Customers), verification results, risk scores, reason codes, and recommendations. Socure may generate this information based on processing the personal information described in this chart.

When our Customers use Customer-Enabled Partners within a workflow, these partners may return information to Socure for a specific transaction after processing the personal information detailed in this chart.

 

California Residents: Under the California Consumer Privacy Act (CCPA), we’re required to let you know that information described above may also fall under these categories:  Personal Information Categories Listed in the California Customer Records Statute (Cal. Civ. Code § 1798.80(e)); Internet or Other Electronic Network Activity Information; Audio, Electronic, Visual, Thermal, Olfactory, or Similar Information; Inferences; and Sensitive Personal Information. In addition, California uses different terms to describe equivalent concepts in other laws. 

How We Use Your Personal Information

We use your personal information, in accordance with law and our Customer contracts, to verify identities, prevent fraud, keep our Services secure, and improve how our products work. Specifically, this includes:

  • performing identity verification and fraud prevention services on behalf of our Customers, including comparing the identifiers you provide during a transaction against the identifiers in any documents you submit to us;
  • providing, maintaining, and enabling sharing of the data in your Socure Pass account;
  • helping ensure the security and integrity of the Services, including detecting anomalous behavior and automated or AI agent traffic (for example, a transaction completed in a fraction of your typical time, from an unfamiliar device or location, or from a bot rather than a person);
  • identifying and repairing errors that impair Services functionality or performance;
  • conducting internal research to develop, improve, test, or repair our Services or related technology, including using device, browser, and network information to guide you through a transaction (e.g., matching your language settings) or flag higher-risk locations; and
  • creating, maintaining, and improving derived insights and network/graph-based risk intelligence (including across our consortium of Customers) to support fraud prevention, identity verification, and security.

Biometric information. Where a product (e.g. DocV) involves document or selfie verification, we use biometric information such as facial landmarks and facial embeddings derived from your photos to guide you to a usable photo in real time (e.g., “move your phone closer”); compare your selfie to your identity document; and check whether we’ve seen you before, to support re-verification. Identity documents and images may also be used to train and test machine learning models and to maintain a record of images linked to repeated fraudulent activity. Where we develop agent-classification or agent-trust features, we may train those models using data collected.

Device and browser integrity signals. To detect anomalous behavior, help ensure the security of the Services, and classify whether traffic originates from a human, bot, or AI agent, we may analyze technical signals collected from your device, browser, or network. Where we detect signs of automated activity, we may also collect these signals from browser tabs or windows that are not actively in use, to assess whether that activity is automated.

Where permitted or required by law, we may also use your personal information to:

  • comply with legal obligations, such as fulfilling data rights requests;
  • respond to a subpoena, investigation, or lawful request from a government authority;
  • cooperate with law enforcement on suspected violations of law;
  • investigate, establish, or defend legal claims; and
  • carry out internal operations consistent with your reasonable expectations and our provision of the Services.

Biometric information Socure processes does not meet the definition of “Consumer Health Data” under U.S. state health privacy laws, because it’s used to prevent, detect, and respond to security incidents, identity theft, and fraud.

Lawful Basis for Processing as Controller (Non-U.S. Persons)

Where Socure acts as a Processor, our Customers are responsible for establishing the lawful basis for that processing; it is addressed in the Customer’s own privacy notice and governed by our data processing agreement with the Customer. The table below sets out Socure’s lawful basis only for the purposes where Socure acts as a controller:

Purpose UK/EEA Basis Canada Basis
To create and maintain your Socure Pass account and enable you to share your verified identity data with Customers you choose Consent  Implied consent
Create, maintain, improve and provide insights and network/graph-based risk intelligence across our consortium of Customers, to detect and prevent fraud and improve identity verification Legitimate interests (for fraud prevention) Implied consent
To classify whether traffic originates from a human or an automated/AI agent, and to establish and maintain a trust assessment for that agent Legitimate interests  Implied consent 
To test our products for bias and measure the fairness of outcomes across demographic groups (which includes the processing of characteristics of protected classifications) Explicit consent for directly-provided protected characteristics;

Substantial public interest for inferred protected characteristics.

Express consent 
To perform biometric identity verification through DocV, including comparing your selfie to your identity document Explicit consent Express consent
Training/testing ML models and maintaining a record of images linked to repeated fraudulent activity, including for agent-classification  Explicit Consent Express consent
Data rights request verification & response Legal obligation Legal obligation

 

Where Socure relies on legitimate interests, we take into consideration your reasonable expectations based on your relationship with our Customers, and balance them against Socure’s needs to support our Customers’ requests to validate identities, assess risk, and prevent, detect, protect or defend against, or respond to security incidents, identity theft, fraud, harassment, or malicious, deceptive, or illegal activities.

For information about how we use personal information when you visit our website or engage with our marketing content, see our Website Privacy Notice.

How We Disclose Your Personal Information

The following table describes the recipients to whom Socure may disclose your personal information in connection with the Services, the purposes for the disclosure, and the categories of personal information disclosed.

Recipients of Personal Information and

Purpose(s) for Disclosure

Categories of Personal Information Disclosed
Customers may receive your personal information for the purpose of verifying your identity and preventing fraud. 
  • Identifiers
  • Financial Account and Transaction Information
  • Characteristics of protected classifications
  • Device, Browser, and Network Information, including Geolocation Data
  • Behavioral data and inferences about how you typically interact with your device during a session
  • Identity Documents and Images
  • Additional Documents
  • Verification Results and Risk Insights
Third-Party Service Providers may receive your personal information for the purpose of:  (a) supporting Socure’s provision of the Services; and/or (b) storing information in the cloud.
  • Identifiers
  • Financial Account and Transaction Information
  • Biometric information (cloud storage only)
  • Characteristics of protected classifications (cloud storage only)
  • Device, Browser, and Network Information, including Geolocation Data (cloud storage only)
  • Behavioral data and inferences about how you typically interact with your device during a session (cloud storage only)
  • Identity Documents and Images
  • Additional Documents
Customer‑Enabled Partners may receive your personal information for the purpose of executing Customer-configured workflows (which may include identity verification, fraud prevention, or compliance checks) and returning results to our Customer.
  • Identifiers
  • Financial Account and Transaction Information
  • Characteristics of protected classifications
  • Device, Browser, and Network Information, including Geolocation Data
  • Behavioral data and inferences about how you typically interact with your device during a session
  • Identity Documents and Images
  • Additional Documents
  • Verification Results and Risk Insights
Corporate Subsidiaries and Affiliates may receive your personal information for the purpose of:  (a) supporting Socure’s provision of the Services; (b) internal research, such as studying fraud and identity trends over time; (c) performing bias and fairness testing; and/or (c) training, development, validation, and/or improvement of machine learning models.
  • Identifiers
  • Financial Account and Transaction Information
  • Biometric information
  • Characteristics of protected classifications
  • Device, Browser, and Network Information, including Geolocation Data
  • Behavioral data and inferences about how you typically interact with your device during a session
  • Identity Documents and Images
  • Additional Documents
  • Verification Results and Risk Insights

 

How Long We Retain Your Information

Fraudsters can reuse the same identity documents and selfies across hundreds of fraudulent attempts over time, so Socure retains certain information long enough to catch these patterns. The chart below summarizes the maximum retention periods for the personal information we collect and generate across our Services, including to verify identities and prevent fraud on behalf of our Customers.

Categories of Personal Information Retention Period
Identifiers No more than 7 years from collection
Financial Account and Transaction Information No more than 7 years from collection
Biometric information No more than 1 year generally from your last interaction with Socure (or 2 years if flagged as suspected fraud, a security incident, or high risk)
Characteristics of protected classifications No more than 3 years from your last interaction with Socure
Device, Browser, and Network Information, including Geolocation Data No more than 7 years from collection
Precise Geolocation No more than 3 years from collection; then truncated, meaning precise coordinates are removed, and general geolocation retention schedule will apply
Behavioral data and inferences about how you typically interact with your device during a session No more than 7 years from collection
Identity Documents and Images No more than 1 year generally from your last interaction with Socure (or 2 years if flagged as suspected fraud, a security incident, or high risk)
Additional Documents No more than 7 years from collection
Verification Results and Risk Insights No more than 7 years from derivation or generation

 

Your personal information may be retained for a shorter period than outlined above if deletion is required by law or contract, or if the purpose it was collected for has expired.

Special Notice re Data Rights Requests: We delete any personal information used to verify your identity for a data rights request within 7 days of verification. Records of the request itself, and our compliance with it, are kept in accordance with applicable law.

How We Protect Your Information

Socure uses commercially reasonable physical, electronic, and procedural safeguards to protect information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction, in accordance with applicable law, and we require our Customers and Third-Party Service Providers to do the same. Biometric information receives the same rigorous privacy and security protections as other sensitive personal information. 

This includes encryption in transit and at rest, strict access controls, data minimization, and data governance procedures. Socure’s data protection practices are audited on a recurring basis, and we maintain ISO 27001 and SOC 2 Type 2 certifications. While we try our best, no safeguard can fully guarantee against a security incident.

Where We Store and Transfer Your Personal Information

Socure stores your personal information in the United States. If you are not already located in the United States, your personal information may be transferred to and processed in the United States. Where Socure uses Third-Party Service Providers, they may process personal information in the United States and other countries such as the Philippines. Socure also has employees located in India, United Kingdom and Europe who may access personal information in connection with providing the Services. When we transfer your personal information internationally, we put appropriate safeguards in place, such as contractual commitments, consistent with applicable law, to help protect your data.

Where personal information is transferred from the European Economic Area to the United States, that transfer is generally made under the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework. Where personal information is transferred from the United Kingdom, that transfer is generally made under the UK’s own adequacy regulations recognizing the UK Extension to the EU-U.S. Data Privacy Framework. Where personal information is transferred from Switzerland, that transfer is generally made under the Swiss Federal Council’s adequacy decision for the Swiss-U.S. Data Privacy Framework.

Where a transfer isn’t covered by an applicable adequacy decision, Socure relies on appropriate safeguards, such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum, together with supplementary measures where appropriate.

Data Privacy Frameworks

Socure complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), its UK Extension, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), as set forth by the U.S. Department of Commerce. Socure has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles for personal information received from the EU (and, via the UK Extension, from the UK and Gibraltar), and to the Swiss-U.S. DPF Principles for personal information received from Switzerland. Socure is subject to the investigatory and enforcement powers of the Federal Trade Commission.

Under these Frameworks, EU, UK, and Swiss individuals have the right to confirm whether we hold personal information about them in the United States, to access that information, and to correct, amend, or delete it. To exercise any of these rights, or to request that we limit the use and disclosure of your personal information, submit a request via this form. We will respond to removal requests within a reasonable timeframe.

Before sharing your data with third parties (other than our agents) or using it for a new, incompatible purpose, we’ll give you the opportunity to opt out. For sensitive data, we’ll ask you to opt in.

In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including for national security or law enforcement purposes.

Socure remains responsible under the Data Privacy Framework Principles for personal data it receives in the U.S. and subsequently transfers to a third party — including where that third party processes it in a manner inconsistent with the Principles, unless Socure proves it wasn’t responsible for the event causing the harm.

If any term in this Privacy Notice conflicts with the EU-U.S. DPF Principles or the Swiss-U.S. DPF Principles, those Principles govern. Learn more about the EU-U.S. DPF program here, and verify Socure’s certification here.

How to Contact Us

Please do not email us your identity documents, selfies, or other personal information. If you are having trouble submitting your documents or need help troubleshooting or understanding the outcome of a specific transaction, please contact the Customer who sent you to us.

To contact the Socure Privacy team, including our Data Protection Officer (DPO), you may email privacy@socure.com or call 1-888-690-3709. Our DPO is Socure’s General Counsel and VP of Legal, Aviad Levin-Gur.

Pursuant to Article 27 of the General Data Protection Regulation (GDPR), Socure has appointed the European Data Protection Office (EDPO) as its GDPR Representative in the EU. You may contact EDPO regarding matters pertaining to the GDPR: (1) by using EDPO’s online request form; or (2) by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.

Pursuant to Article 27 of the UK GDPR, Socure has appointed the EDPO UK Ltd as its UK GDPR representative in the UK. You may contact EDPO UK regarding matters pertaining to the UK GDPR and/or complaints under section 164A of the Data Protection Act 2018 (“DPA 2018”) as amended by the Data (Use and Access) Act 2025 (“DUAA”): (1) by using EDPO’s online request form; or (2) by writing to EDPO UK at Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom.

Please contact us if you have any complaints. If you are a UK and EU individual and your complaint is not addressed by us within the applicable timeframe, you may contact the EDPO by using the relevant EDPO’s online request forms above. If your complaint under the EU-U.S. (including the U.K. extension) and Swiss-U.S. DPF isn’t resolved, you may refer it, free of charge, to Data Privacy Framework Services, operated by BBB National Programs — visit this website for details. If it still isn’t resolved, you may, under certain conditions, invoke binding arbitration for residual claims — see here for more information.