Privacy Policy
BioPay ("we", "us", or "our") operates the BioPay mobile application. This Privacy Policy explains what personal data we collect, why we collect it, and how we protect it. By using BioPay you agree to this policy.
1. Data We Collect
We collect the following categories of personal data:
- Identity data: first name, last name, username
- Contact data: email address, phone number
- Biometric data: facial embeddings generated during face enrollment (mathematical representations of your face — not raw images)
- Payment data: payment card last four digits, card network, issuing bank (we do not store full card numbers)
- Transaction data: payment history, amounts, merchants, timestamps
- Device data: device name, platform (iOS/Android), session tokens
2. How We Use Your Data
- To authenticate you and process payments via facial recognition
- To send transaction notifications and security alerts
- To detect and prevent fraud
- To comply with legal and regulatory obligations
We do not sell your personal data to third parties. We do not use your data for advertising.
3. Biometric Data
BioPay collects facial embeddings solely for payment authentication. Raw images are processed on-device or on our secure servers and are not retained after embedding generation. Facial embeddings are stored encrypted and are never shared with third parties. You may delete your biometric data at any time from the Face Pay screen in the app.
4. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, your personal data is anonymised within 24 hours. Transaction records may be retained for up to 7 years for regulatory compliance.
5. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and personal data
- Withdraw consent at any time (e.g. unenroll from Face Pay)
To exercise these rights, use the in-app settings or contact us at privacy@biopay.ge.
6. Security
We use industry-standard encryption (TLS in transit, AES-256 at rest) and store credentials using secure hashing. Access to production data is restricted to authorised personnel.
7. Third-Party Services
BioPay integrates with Georgian banking partners for card processing. These partners process card data under their own privacy policies and applicable Georgian financial regulations.
8. Children
BioPay is not intended for users under 18. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy. We will notify you of material changes via the app. Continued use after notification constitutes acceptance.
10. Contact
For privacy questions: privacy@biopay.ge
BioPay · Georgia