Help · biometric processing
Biometric data, plainly: what we keep, what we delete.
PodiumBase can match your face to race photos using AWS Rekognition. This page explains what data we process, how long we keep it, and your rights. We last updated it on June 6, 2026.
Biometric processing FAQ
- What biometric data does PodiumBase process?
- When an athlete uploads a selfie to find race photos, PodiumBase computes a face embedding — a mathematical representation of facial geometry — and compares it against embeddings from photographers’ uploaded race photos for the same event. The embeddings are biometric identifiers under U.S. state laws including BIPA (Illinois), CUBI (Texas), and RCW 19.375 (Washington). Embeddings are scoped per event; PodiumBase does not cross-match faces between events, sell or rent biometric data, or share embeddings outside AWS Rekognition (the sub-processor under a written data-processing agreement).
- How long does PodiumBase retain biometric data?
- Face embeddings are stored in a per-event AWS Rekognition Collection and are permanently deleted when the event closes, on explicit race-director purge, or within 60 days of the event date — whichever occurs first. Raw selfie images uploaded by athletes are permanently deleted within 60 seconds of matching; only matched-photo IDs are returned. In all cases, no biometric data is retained beyond 3 years from the data subject’s last interaction with the service.
- Which state biometric laws apply to PodiumBase?
- For V1, the selfie photo-search surface is gated for visitors located in Illinois pending external-counsel review against current BIPA case law. Illinois athletes can still find their race photos by bib-number search. Texas and Washington residents see the normal flow, governed by CUBI and RCW 19.375 respectively. EU/UK residents retain GDPR rights independent of this default flow.
- How do I opt out or delete my biometric data?
- You can opt out of biometric processing at any time in your athlete settings. To delete face data PodiumBase has already processed, email privacy@podiumbase.io or use the data-deletion request flow in your account. Race directors can purge an entire event’s Rekognition Collection from event settings.
- How is my consent recorded?
- The consent step in the selfie-search modal stamps a consent record with the exact retention-policy text version the visitor saw at submit time. The policy itself is publicly posted on this FAQ page per BIPA §15(a). The retention block is version-stamped (FAQ_BIOMETRIC_RETENTION_BLOCK_VERSION) so the policy text any historical consent referenced is forensically reproducible from the audit row alone.
- Who can I contact about biometric data at PodiumBase?
- Email privacy@podiumbase.io for privacy questions or to exercise a data right. For the full data-handling account, see the PodiumBase Privacy Policy at /legal/privacy.
What we process
When an athlete uploads a selfie to find their race photos, we compute a face embedding (a mathematical representation of facial geometry) and compare it against the embeddings extracted from photographers’ uploaded race photos for the same event. The embeddings are biometric identifiersunder U.S. state laws including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington’s RCW 19.375.
Face embeddings are scoped to a single race’s AWS Rekognition Collection. We do not cross-match faces between events. We do not sell or rent biometric data. We do not share embeddings with third parties beyond AWS Rekognition (our sub-processor, under a written data-processing agreement).
Retention schedule for biometric data
- Face embeddings (mathematical representations) are stored in a per-event AWS Rekognition Collection.
- Embeddings are permanently deleted when the event closes, OR upon explicit race director purge action, OR within 60 days of the event date, whichever occurs first.
- Raw selfie images uploaded by athletes are permanently deleted within 60 seconds of matching. Only matched-photo IDs are returned.
- In all cases, no biometric data is retained beyond 3 years from the data subject’s last interaction with the service.
State biometric laws
For our V1 launch, the selfie photo-search surface is gated for visitors located in Illinois. Illinois athletes can still find their race photos by searching their bib number; the face-matching upload option is hidden in that state pending external counsel review of our consent flow against the latest BIPA case law. Texas and Washington residents see the normal flow.
Your rights
You can opt out of biometric processing at any time in your athlete settings. If you want us to delete face data we’ve already processed for you, email privacy@podiumbase.io or use the data-deletion request flow in your account.
Race directors can purge an entire event’s Rekognition Collection from event settings. EU/UK residents retain GDPR rights (access, erasure, portability, objection to processing) independent of our default flow.
Contact
For privacy questions or to exercise a data right, email privacy@podiumbase.io. For a full account of how we handle data, see our Privacy Policy.