SocureNewsletter_August2025_MicrositeHero (1)

Website Privacy Notice

Effective date: October 01, 2026

 
This Website Privacy Notice (“Notice”) describes how Socure Inc. (collectively, “Socure,” “we,” “us,” or “our”) collects, uses, and discloses personal information about website visitors, prospective business customers, and other individuals who engage with our marketing and sales content — including our websites and digital content (the “Sites”), demo or trial systems, white papers, webinars, in-person or virtual events, and our chatbot. This Notice includes our Cookie Policy.

This Notice applies when we market and sell our digital identity verification and fraud prevention products and services (“Services”) to you and when you visit and engage with us online or in person. It does not apply to personal information Socure processes to provide identity verification and fraud prevention services on behalf of the businesses that use Socure’s identity verification Services (“Customer“), including through document and biometric verification — that processing is described in our separate Global Services Privacy Notice. If you are both a website visitor or prospect and someone whose identity Socure verifies on behalf of a Customer, both notices may apply.

Subject to applicable law, we may update this Notice from time to time by publishing a new version on this website.

How This Works

When you visit our Sites, download a white paper, attend a webinar or in-person event, request a demo, or chat with us, we collect information about that interaction so we can follow up with you, understand what you’re interested in, and market our Services to you and to other people at your company. It’s simply how we get to know you as a visitor or prospective business customer.

This is different from the identity verification data described in our Global Services Privacy Notice. 

Socure does not sell or share your personal information. We also don’t market or advertise directly to consumers in connection with the identity verification services we provide our Customers — the marketing described in this Notice relates to visitors, prospects, and business contacts.

Socure sometimes decides why and how your data is used (“Controller“), and sometimes processes it on a Customer’s instructions (“Processor“) — which matters because it determines who you’d contact about your data. For the processing described in this Notice, Socure acts as a Controller: we decide why and how this information is used, rather than following a Customer’s instructions the way we do when verifying your identity on a Customer’s behalf.

A quick note on terms: “Controller” and “Processor” are the terms used under most privacy laws around the world, including most U.S. state privacy laws, and are used throughout this Privacy Notice as the global standard. If you live in California, your state’s privacy law, the California Consumer Privacy Act, uses different terms instead: “Business” and “Service Provider,” defined by what your contract with us says rather than by who decides how your data is used. We use Controller/Processor as shorthand throughout this Privacy Notice for clarity; where a specific law, whether California’s, another state’s, or another country’s, gives you different rights or imposes different obligations on us, we say so specifically.

Your Rights & Choices

Depending on where you reside, you may have the right to know, access, correct, delete, restrict the processing of, and transfer your personal information, and to opt out of the sale or sharing of your information, including for targeted advertising. If you’ve consented to any processing, you can withdraw that consent at any time. If you exercise these rights, you have the right not to be treated in a discriminatory way. You also have the right to lodge a complaint with your applicable regulator.

To exercise any of these rights, visit our Data Rights Form. Because data rights vary by where you live, the form lists a variety of rights that may or may not apply to you, and we may not be able to fulfill a request if the law doesn’t grant you the right you’re attempting to exercise.

We recognize Universal Opt-Out Mechanisms, such as the Global Privacy Control (GPC) signal, as a valid way to opt out of the sale or sharing of your information, including for targeted advertising, where required by applicable law.

You may designate an authorized agent to submit a request on your behalf, subject to verification. To help protect your data, we may need to verify your identity before completing your request. For questions, contact us at privacy@socure.com.

Personal Information We Collect (and the Sources)

We collect personal information about you from you directly, from data vendors, and from our Third-Party Service Providers, when you engage with us via our Sites or in person. The chart below shows what we collect for marketing and sales purposes, and where it comes from:

Categories of Personal Information Collected Sources of Information Collected
Identifiers,

such as legal name, alias or nickname, mailing or residence address, email address, or other similar identifiers.

You, the Customers,

may provide this information to Socure when you engage with Socure via the Sites.

Data Vendors and Third-Party Service Providers

may provide this information to Socure.

Commercial Information,

such as information about your company, including IP address, information about which Socure Services you purchase or inquire about, chatbot transcripts, your engagement history with Socure’s website and with our general marketing efforts, such as webinars you attend, and which Socure content you download.

You

provide this information to Socure when you engage with Socure via the Sites or via in-person or virtual events.

Data Vendors and Third-Party Service Providers

may provide this information to Socure.

Browser and Network Information,

including Geolocation Data, such as Internet Protocol (IP) address, language and time zone settings, referrer URL, and other information about the browsers and network you use when interacting with the Sites.

You

provide this information to Socure when you engage with Socure via the Sites or via in-person or virtual events.

Data Vendors and Third-Party Service Providers

may provide this information to Socure.

Behavioral data and inferences about how you typically interact with the Sites and marketing content during a session,

including session timing, pages viewed, links clicked, content downloads, webinar attendance, and similar engagement information.

You

provide this information to Socure when you engage with Socure via the Sites or via in-person or virtual events.

Data Vendors and Third-Party Service Providers

may provide this information to Socure.

Communication Content,

such as the communications you have with Socure and our Services, including interaction with our chatbots.

You

provide this information to Socure when you engage with Socure via the Sites or via in-person or virtual events.

 

California Residents: Under the California Consumer Privacy Act (CCPA), we’re required to let you know that information described above may also fall under these categories: Personal Information Categories Listed in the California Customer Records Statute (Cal. Civ. Code § 1798.80(e)); Internet or Other Electronic Network Activity Information; Audio, Electronic, Visual, Thermal, Olfactory, or Similar Information; Inferences; and Sensitive Personal Information. 

How We Use This Information

We don’t market or advertise directly to consumers in connection with the identity verification services we provide our Customers. If you engage with content on our Sites — like a demo, a white paper, a webinar, or our chatbot — you may receive marketing or advertising communications from Socure in accordance with this Notice.

We do not use sensitive categories of information, such as health, religious belief, or political affiliation, to select or personalize marketing content.

The table below sets out the lawful basis for each purpose.

Purpose UK/EEA Basis Canada Basis
Operating necessary cookies and core site functionality Legitimate interests Implied consent
Placing non-essential cookies (analytics, marketing) and other tracking technologies (pixels, tags, fingerprinting) Consent Express consent
Marketing communications to visitors, prospects, and business contacts (e.g., following a demo request, webinar registration, or content download) Consent and legitimate interests  Implied consent*
Data rights request verification & response Legal obligation Legal obligation
To classify whether traffic originates from a human or an automated/AI agent, and to establish and maintain a trust assessment for that agent Legitimate interests  Implied consent 

 

*Where you already have an existing business relationship with Socure, we may rely on implied consent for a limited period as permitted under Canada’s Anti-Spam Legislation (CASL).

Where Socure relies on legitimate interests, we take into consideration your reasonable expectations based on your relationship with Socure, and balance them against our interest in operating a functioning website and reaching prospective business customers with relevant information about our Services. You may object to this processing at any time, including via the Marketing Preference Center, unsubscribe link in any marketing communication that we send to you or through our Cookie Preferences.

How We Disclose This Information

The following table describes the recipients to whom Socure may disclose your personal information for sales and marketing purposes, the purposes for the disclosure, and the categories of personal information disclosed.

Recipients of Personal Information and Purpose(s) for Disclosure Categories of Personal Information Disclosed
Third-Party Service Providers

may receive your personal information for the purpose of: (a) supporting Socure’s efforts to market and sell the Services to Customers; (b) storing information in the cloud; and/or (c) training, development, validation, and/or improvement of machine learning models.

• Identifiers

• Commercial Information

• Browser and Network Information

• Behavioral data and inferences about how you typically interact with your device during a session

• Communication Content

Corporate Subsidiaries and Affiliates

may receive your personal information for the purpose of: (a) supporting Socure’s provision of the Services; (b) internal research; (c) performing bias and fairness testing; and/or (d) training, development, validation, and/or improvement of machine learning models.

• Identifiers

• Commercial Information

• Browser and Network Information

• Behavioral data and inferences about how you typically interact with your device during a session

• Communication Content

 

Targeted Advertising. Any targeted advertising described in this Notice relates to visitors to our Sites and business-contact marketing activities, not to personal information processed to provide identity verification and fraud prevention services on behalf of our Customers. To the extent we use Third-Party Service Providers to assist with targeted (cross-contextual behavioral) advertising, they’re contractually restricted to process the information solely on our behalf, and may not use it for their own independent purposes. We may disclose to them your identifiers, professional or employment-related information, and/or personal information categories listed in the California Customer Records statute, alone or combined with information from other sources like our data vendors, and they may use various tracking technologies.

No Selling or Sharing. As noted above, Socure does not sell or share, and has not sold or shared in the preceding 12 months, any personal information, as those terms are defined by applicable law. Socure also does not have actual knowledge that it sells or shares the personal information of consumers under 16 years of age. Socure does not disclose sensitive personal information for purposes other than those specified in section 7027(m) of the California Consumer Privacy Act Regulations.

How Long We Retain This Information

The chart below summarizes the maximum retention periods for the personal information we collect and use for sales and marketing purposes.

Categories of Personal Information Retention Period
Identifiers As long as you are a Customer of Socure, and thereafter for 5 years
Commercial Information As long as you are a Customer of Socure, and thereafter for 5 years
Browser and Network Information, including Geolocation Data No longer than 25 months from collection
Behavioral data and inferences about how you typically interact with the Sites during a session No longer than 25 months from collection
Communication Content As long as you are a Customer of Socure, and thereafter for 5 years

 
Your personal information may be retained for a shorter period than outlined above if deletion is required by law or contract, or if the purpose it was collected for has expired.

How We Protect This Information

We protect the personal information described in this Notice using the same safeguards described in our Global Services Privacy Notice — including encryption in transit and at rest, strict access controls, and recurring audits under our ISO 27001 and SOC 2 Type 2 certifications. While we try our best, no safeguard can fully guarantee against a security incident.

Where We Store and Transfer Your Information

Socure stores personal information in the United States, and it may be transferred to and processed there if you’re located elsewhere. Where required, we rely on the same cross-border transfer safeguards — including the EU-U.S., UK, and Swiss Data Privacy Frameworks and Standard Contractual Clauses — described in our Global Services Privacy Notice.

Cookie Policy

Socure’s Sites use cookies to operate core site functionality, remember your preferences, measure how our Sites and marketing content perform, and help us show you more relevant content and ads. Where required by applicable law, we’ll ask for your consent before placing non-essential cookies, including analytics and marketing cookies.

If you want to disable cookies in Chrome, go to Settings, then Privacy and Security, then Cookies and other site data, and choose to block third-party cookies or all cookies. In Safari on a Mac, go to Preferences, then Privacy, and choose to block cookies. On an iPhone or iPad, go to Settings, then Safari, and then to the Advanced or Privacy & Security section to manage cookies. In Firefox, go to Settings, then Privacy & Security, and adjust Enhanced Tracking Protection and cookie settings. For other browsers, check with your provider to find out how to disable cookies. You can also manage your preferences at any time through our Cookie Preferences, available via the icon in the bottom-left corner of the page. Where applicable, you may also use recognized opt-out preference signals.

Because cookies are used throughout our Sites, disabling them may prevent you from using certain features or functionality.

What are Cookies?

Cookies are small text files placed on your device by websites you visit. They’re widely used to make websites work more efficiently, and to give site owners information about how their site is used.

Types of Cookies We Use

Socure uses four types of cookies when you visit the Sites: 

(1) Necessary Cookies — essential for the website to function properly, enabling things like page navigation and access to secure areas. 

(2) Preferences Cookies — remember information that changes how the website behaves or looks, like your preferred language or region. 

(3) Statistics/Analytics Cookies — help us understand how visitors interact with the Sites so we can measure and improve performance; some are set by third-party analytics providers on our behalf. 

(4) Marketing Cookies — track visitors across websites so we can display ads that are more relevant to you, including third-party cookies set by advertising partners, who may collect information about your online activity over time and across different websites.

Other Tracking Technologies — Beyond cookies, our Sites and marketing communications may also use pixels, web beacons, tags, device fingerprinting, tracking links, and similar technologies that operate in a comparable way for the same purposes described above, this includes storing or accessing information on your device, or recognizing your device or browser across visits. Our Cookie Preferences lets you manage these technologies to the same extent it manages cookies; however, some tracking links (for example, in marketing emails) may not be controllable through browser or Cookie Preferences, and can generally only be avoided by not interacting with that content.

How to Contact Us

Please do not email us your identity documents, selfies, or other personal information. If you are having trouble submitting your documents or need help troubleshooting or understanding the outcome of a specific transaction, please contact the Socure Customer who sent you to us.

To contact the Socure Privacy team, including our Data Protection Officer (DPO), you may email privacy@socure.com or call 1-888-690-3709. Our DPO is Socure’s General Counsel and VP of Legal, Aviad Levin-Gur.

Pursuant to Article 27 of the General Data Protection Regulation (GDPR), Socure has appointed the European Data Protection Office (EDPO) as its GDPR Representative in the EU. You may contact EDPO regarding matters pertaining to the GDPR: (1) by using EDPO’s online request form; or (2) by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.

Pursuant to Article 27 of the UK GDPR, Socure has appointed the EDPO UK Ltd as its UK GDPR representative in the UK. You may contact EDPO UK regarding matters pertaining to the UK GDPR and/or complaints under section 164A of the Data Protection Act 2018 (“DPA 2018”) as amended by the Data (Use and Access) Act 2025 (“DUAA”): (1) by using EDPO’s online request form; or (2) by writing to EDPO UK at Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom.