Skip to content
VETO
SampleSecurity
Run one file with Sebastian
SampleSecurityRun one file with Sebastian

Identity and Biometric Information Notice

This notice explains an optional identity workflow, including what Persona may collect, why it is used, who receives it, and when it must be destroyed.

Effective August 13, 2026

1. When this notice applies

This notice applies only when an escrow office enables a Veto workflow that clearly asks you to photograph an identity document and take a selfie or video through Persona. The public notice does not itself give consent. Before Persona opens, Veto requires separate acceptance of its Terms and this notice and records the notice versions and acceptance time. Persona must also show any provider notice required for the selected check.

If the workflow does not ask for an ID image, selfie, or video, Veto does not collect biometric information through that workflow.

2. Information collected

Depending on the enabled identity check, Persona may collect or generate:

  • a photograph or scan of a government-issued identity document;
  • a selfie photograph or short video;
  • face geometry or another mathematical representation derived from the selfie, video, or identity-document image;
  • document, device, liveness, and fraud signals; and
  • the inquiry identifier, status, result, and supporting metadata.

Depending on applicable law, some derived information may be a biometric identifier or biometric information. Veto does not use this workflow to collect a fingerprint, retina or iris scan, or voiceprint.

Persona performs the capture and comparison. Veto ordinarily receives the inquiry ID, result, limited document or identity metadata, and source evidence needed for the office’s review. Veto does not ordinarily copy a raw biometric template into its active systems.

3. Purpose

The information is used only to:

  • perform the identity check requested for the specific transaction workflow;
  • compare the presented identity evidence and return a result or limitation;
  • prevent, detect, or investigate fraud, impersonation, abuse, or a security incident;
  • give the office limited source evidence for its review; and
  • meet applicable legal, security, and record-of-consent duties.

The office decides. Veto records the review.

An identity-provider result is not Veto’s independent authentication, approval, authorization, or guarantee. It does not establish authority to act, ownership of a bank account, or that a payment instruction is safe.

4. Disclosure and sale

Veto may disclose this information to Persona and infrastructure providers needed to perform and secure the workflow; to the customer office that requested the workflow; on the customer’s documented instruction; or when law, a valid warrant, subpoena, or court order requires it.

Veto does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. Veto does not use them for advertising, data brokerage, general-purpose model training, credit or eligibility decisions, or an unrelated commercial purpose.

5. Retention and permanent destruction

Veto’s policy is to permanently destroy biometric identifiers and biometric information when the initial purpose for collecting them has been satisfied. Unless a valid warrant, subpoena, court order, or other law requires a different period, destruction must occur no later than:

  • 90 days after collection, or an earlier date required by the customer’s signed data schedule; or
  • three years after your last interaction with Veto,

whichever occurs first.

Veto will delete copies in its active systems and instruct Persona and direct providers processing the information for Veto to delete their copies. Routine disaster-recovery backups may retain deleted information until they cycle out; they are not used for ordinary processing, and deletion is reapplied before restored data becomes available.

Veto may retain a non-biometric record that the workflow occurred, the provider’s outcome and stated limitations, consent evidence, deletion date, and a non-reversible deletion receipt when needed for the customer’s Review Record, security, or legal compliance. That record must not contain a biometric template or raw selfie video.

6. Security

Veto requires biometric information to be stored, transmitted, and protected using a reasonable standard of care and at least as carefully as other confidential and sensitive information. Safeguards include access restrictions, encryption in transit, provider contracts, customer separation, and incident-handling procedures.

7. Your choice

Review the disclosure in the identity flow before you consent. You may decline and ask the office that sent the Transaction Link whether it offers an alternative procedure. Declining may prevent completion of that particular Veto identity workflow, but Veto does not decide whether the office will accept an alternative.

To request access or deletion, contact the office that requested the check or email support@tryveto.com. Veto may verify your identity before completing a request.

8. Contact

Heyneman Company, doing business as Veto
1111b S Governors Avenue, STE 29920
Dover, DE 19904 US
support@tryveto.com · +1 (818) 533-4120

PrivacyTermsSubprocessors
PrivacyTermsCookiesAccessibilitySMSContact

Heyneman Company
1111b S Governors Avenue, STE 29920
Dover, DE 19904 US

Money leaves. The record stays.