Skip to main content

This Privacy Policy explains how Trust Swiftly (“we,” “us,” or “our”) collects, uses, and discloses information about you when you visit our website (TrustSwiftly.com) (the “Site”), use our identity verification services (the “Services”), or otherwise interact with us.

This policy is divided into two parts to clarify our role in different contexts:

  • Part I applies to the personal information of individuals (“End-Users”) whose identities are verified using our Services. In this situation, we generally act as a data processor or service provider on behalf of our business customers (“Customers”), who determine why and how the verification is used.
  • Part II applies to the personal information we collect from our Customers’ representatives and visitors to our Site for our own purposes. In this situation, we act as a data controller.

Table of Contents

  1. Part I: Information We Process for Our Customers (End-User Data)
  2. Part II: Information We Process for Ourselves (Customer & Site Visitor Data)
  3. Cookies and Tracking Technologies
  4. Your Privacy Rights and Choices
  5. International Data Transfers
  6. Data Security and Retention
  7. Other Important Information
  8. Contact Us

1. Part I: Information We Process for Our Customers (End-User Data)

This section describes our processing of personal information of End-Users, which we generally perform on behalf of and at the direction of our Customers. The Customer is responsible for establishing a lawful purpose for the verification, providing required notices, obtaining required consents, and making the final decision based on the verification. The Customer’s privacy notice should be read together with this Policy and explains the Customer’s own use of your information. Trust Swiftly contractually requires Customers to limit digital identity data to the requested verification transaction and prohibits its use for marketing, advertising, profiling unrelated to the verification, or unauthorized sharing. Where applicable law or a digital-wallet provider’s terms treat Trust Swiftly as an independent controller for a particular activity, we are responsible for that processing as described in this Policy.

A. Information We Collect from End-Users

At the direction of our Customer, we collect the following types of information from you to perform an identity verification:

  • Identity Information: This can include your full name, date of birth, phone number, email address, physical address, images of your physical government-issued identity documents (like a driver’s license, passport, or national ID card), and information contained in those documents.
  • Biometric Information: With your explicit consent, we may ask you to provide one or more photos or a short video of yourself. Videos are collected specifically for liveness detection and anti-spoofing measures (e.g., ensuring the user is a live human and not utilizing a photograph, mask, or deepfake). We use facial recognition technology to extract a scan of your facial geometry from this media. Our Customer, as the data controller, is responsible for ensuring that the required notice is provided and explicit written consent is obtained before our collection of biometric information. This biometric data is used for the sole purposes of comparing it to the photo on your identity document to help verify your identity (“Verification”) and prevent fraud (“Fraud Prevention”). We do not sell, rent, or trade End-User biometric or identity data or use it for advertising. For specific details on how long we retain this sensitive data, please see the Biometric Data Retention section below.
  • Information from Third Parties: At the direction of our Customer, we may obtain information about you from third-party identity verification services, public records, or fraud-prevention databases to cross-reference and validate the information you provide.
  • Device and Usage Information: We automatically collect information about your device, including your IP address, browser type, and operating system, to assist with Fraud Prevention.
  • Wireless Carrier & Silent Network Authentication (SNA) Information: To confirm that you possess the mobile number you provide and to help prevent fraud, we may verify your number through our verification provider and your mobile carrier, including via Silent Network Authentication (a network-based check that does not require you to enter a code). Where this method is used, you authorize your carrier to use or disclose available account and device information to Trust Swiftly or our service provider solely to identify you or your device and prevent fraud. This may include your name, address, mobile number, account tenure, device details, and a verification result. Your mobile number is shared with the verification provider and carrier for this purpose.

B. Digital IDs and Mobile Driver’s Licenses

If you choose to present a mobile driver’s license (mDL) or another digital identity credential from a compatible wallet, the information requested depends on the credential, the verification method, and the Customer’s legitimate requirements. We do not require every available credential field for every verification. Our Services support data-minimized requests, including a derived or threshold result instead of more detailed underlying information when that result is configured and sufficient for the Customer’s use case. Your device, wallet, or the verification flow will identify the specific information requested before you approve the presentation.

We may retain the information you approve for presentation, the signed cryptographic presentation, the verification result, and limited technical evidence needed to validate the credential, document the transaction, prevent fraud, maintain security, and investigate disputes or security incidents. The notice presented for the transaction or the Customer’s privacy notice will explain whether the information will be retained and the applicable retention period. If the requested information or purpose changes, the request and notice shown before presentation must reflect that change.

Presenting a digital ID is voluntary unless the Customer explains that it is required for the Customer’s product or service. You may decline the wallet request before sharing data and ask the Customer whether another verification method is available. Trust Swiftly does not receive your wallet payment credentials. Your wallet provider and the government or other credential issuer may process information under their own privacy policies.

C. How We Use End-User Information

We process End-User information strictly to provide the Services to our Customers. Our purposes are:

  • To perform identity Verification and Fraud Prevention on behalf of our Customers.
  • To provide the results of the Verification to the Customer that requested it.
  • To secure, troubleshoot, and maintain our Services.

Purpose Limitation: We are committed to data minimization. We do not use End-User data (including identity information and data from digital wallets) for marketing, profiling, or any purpose beyond identity verification and fraud prevention as described herein.

Sensitive Personal Information: Trust Swiftly processes government-issued identity documents, account credentials, precise location in certain verification flows, and biometric information, which may be classified as sensitive personal information under applicable law. We process this information only as reasonably necessary to provide the requested verification, prevent fraud, maintain security, comply with law, and perform other purposes disclosed to you. We do not use sensitive personal information to infer characteristics unrelated to the requested verification. Where a statutory exception does not apply, we will provide any right to limit this processing required by law.

Health Data Disclaimer: We do not collect, process, analyze, or share biometric information or any other data for the purpose of identifying or inferring a physical or mental health status, condition, or diagnosis. Our processing of biometric data is strictly limited to identity verification and fraud prevention.

Aggregated and De-Identified Data: By default, Trust Swiftly does not use Customer Data or End-User data, including biometric identifiers, to train machine learning models. However, with the Customer’s explicit, prior written consent, Trust Swiftly may use specific data (such as images of identity documents not currently supported by our system) to improve our document recognition and fraud-detection capabilities. Such consent may be granted or revoked at any time by the Customer. We may also use aggregated, anonymized, and de-identified usage statistics (such as verification success rates and system performance metrics) to improve the reliability and performance of our Services. Such de-identified data will never contain personally identifiable information or biometric data, and we will not attempt to re-identify it. Notwithstanding the foregoing, identity data and cryptographic payloads obtained via digital wallets are strictly excluded from any system-improvement use. We never use digital wallet data to train machine learning models or improve system capabilities, regardless of Customer consent.

D. Automated Decision Making

Our Services utilize automated logic and algorithms to analyze identity documents and biometric data to verify identities and detect fraud. While many verification checks are fully automated, some verifications may undergo manual review by our team or the Customer’s team, depending on the Customer’s specific configuration and instructions.

Because we act as a data processor, the final decision regarding your verification status (e.g., approving or rejecting your application) is made by the Customer. If you wish to contest the result of an automated verification or request human intervention, please contact the Customer directly.

E. How We Disclose End-User Information

We only disclose End-User information as directed by our Customer or as required by law. This includes disclosures to:

  • Our Customer: We provide the results of the Verification and the data configured for disclosure to the Customer who initiated the identity check. Customers may use digital-wallet data only for the verification purpose disclosed to you and may not sell it or use it for marketing, advertising, or unrelated profiling.
  • Service Providers (Subprocessors): We may engage third parties to assist us in providing the Services, such as cloud hosting providers and communications and identity-verification providers. For example, we use Twilio to deliver SMS and voice one-time passcodes and to perform mobile carrier verification, including Silent Network Authentication. These providers are contractually bound to protect the data and only use it to perform services for us. We maintain a current list of our subprocessors here. We will notify Customers of any material changes to this list.
  • For Legal Reasons: We may disclose your information if we believe in good faith that it is required to comply with a law, regulation, legal process, or governmental request.

2. Part II: Information We Process for Ourselves (Customer & Site Visitor Data)

This section applies to personal information we collect from representatives of our Customers and from visitors to our Site.

A. Information We Collect

  • Account and Contact Information: When a Customer creates an account, requests information, or communicates with us, we collect business contact information such as name, email address, phone number, and company name.
  • Payment Information: When you purchase our Services, our third-party payment processor collects your payment details. We do not store your full credit or debit card information.
  • Communications and Survey Responses: We collect information you provide when you contact our support team, participate in surveys, or otherwise communicate with us.
  • Device and Usage Information: When you interact with our Site, we automatically collect technical information, including your IP address, browser type, operating system, pages visited, and the duration of your activities.

B. How We Use Your Information

We use this information for our legitimate business purposes, including:

  • To Provide and Maintain the Services: To create and manage Customer accounts, process transactions, and provide customer support.
  • To Improve and Personalize Our Services: To understand how our Site is used, develop new products, and improve user experience.
  • For Communication: To respond to your inquiries and send you service-related communications, such as billing and technical notices.
  • For Marketing and Advertising: To provide you with information about our products and services, as permitted by law. You can opt out of marketing communications at any time.
  • For Compliance, Fraud Prevention, and Safety: To enforce our terms, protect our rights, and prevent illegal activity.

Where European, UK, or similar data-protection law applies, our legal bases for this controller processing may include performance of a contract or steps requested before entering a contract, compliance with legal obligations, our legitimate interests in operating and securing our business, and consent where required. You may withdraw consent at any time for future processing, but withdrawal does not affect processing already performed. The Customer determines the legal basis for the End-User verification processing described in Part I.

C. How We Disclose Your Information

We do not sell your personal information for monetary consideration. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We may disclose your information to:

  • Service Providers: We use third-party companies for services such as payment processing, data analysis, marketing, and IT services.
  • For Legal Reasons: We may disclose your information if we believe it is required to comply with the law or to protect the rights, property, or safety of Trust Swiftly, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred.

3. Cookies and Tracking Technologies

We and our third-party partners use cookies, pixel tags, and similar technologies to automatically collect information when you visit our Site. These technologies help us operate our Site, understand user engagement, and support our advertising efforts. You can control the use of cookies at the individual browser level.

Do Not Track Policy: Some web browsers have a “Do Not Track” feature. Except for the Global Privacy Control (GPC) signals discussed below, we do not currently respond to “Do Not Track” browser signals.

We use Google Analytics to process analytics information. You can learn about Google’s practices and opt out by visiting google.com/policies/privacy/partners/ and tools.google.com/dlpage/gaoptout.

4. Your Privacy Rights and Choices

Depending on your jurisdiction, you may have specific rights regarding your personal information. We are committed to facilitating these rights.

A. Rights for End-Users

Because we act as a data processor on behalf of our Customers, you should direct any requests to exercise your privacy rights to the Customer (the business that required you to verify your identity). They are the data controller and are responsible for managing your data. We will assist our Customers in responding to your requests as required by law. Your rights may include:

  • Right to Access, Correct, or Delete: The right to request access to, correction of, or deletion of your personal information under certain conditions.
  • Right to Data Portability: The right to receive a copy of your data in a machine-readable format.
  • Right to Restrict or Object to Processing: The right to request the restriction of or object to the processing of your personal information.
  • Right to Withdraw Consent or Appeal: Where processing is based on consent, you may be able to withdraw it for future processing. In some jurisdictions, you may also appeal a Customer’s refusal to act on your request or contest a decision made using automated processing.

If you presented a digital ID, you may also request an export of the equivalent identity data that the Customer maintains, subject to applicable law and security restrictions. Start with the Customer that requested the verification. You may also contact [email protected] if you cannot identify the Customer or need assistance routing a request. We may need to verify your identity before acting on a request.

B. Rights for Customers and Site Visitors

As a Customer or Site Visitor, you have rights regarding the personal information we control.

  • Right to Opt-Out of Marketing: You can opt out of marketing emails by using the “unsubscribe” link at the bottom of the email. You will continue to receive essential service-related communications.
  • Your U.S. State Privacy Rights: Residents of certain U.S. states have specific rights regarding their personal information. Subject to applicable thresholds and exceptions, you may have the right to:
    • Know / Access: Request to know what personal information we collect, use, and disclose.
    • Correct: Request to correct inaccurate personal information we maintain about you.
    • Delete: Request to delete personal information we have collected from you.
    • Opt-Out of “Sharing” or “Targeted Advertising”: As described in our “Cookies” section, we may use tracking technologies for advertising purposes. This activity may be considered “Sharing” or “Targeted Advertising” under applicable state laws. You have the right to opt-out of this activity.
    • Appeal: Appeal our refusal to act on a privacy request where applicable law provides that right.
  • How to Exercise Your Rights:
    • To exercise your rights to Know, Correct, or Delete, please email us at [email protected].
    • To Opt-Out of Targeted Advertising / Sharing related to tracking technologies, please manage your preferences via our cookie consent banner or by enabling the Global Privacy Control (GPC) signal on your browser.

We will not discriminate against you for exercising any of your privacy rights.


5. International Data Transfers

Your information may be transferred, processed, and stored in countries outside of your own, including the United States, which may have data protection laws that differ from your home country.

When we transfer personal information from the European Economic Area (EEA), United Kingdom (UK), or Switzerland to other countries, we take steps to ensure an adequate level of protection. We rely on legal mechanisms such as the European Commission’s Standard Contractual Clauses (SCCs) and the UK Addendum. We also conduct Transfer Impact Assessments (TIAs) as required to supplement these mechanisms and ensure your information remains protected to a standard equivalent to that in your home country.

6. Data Security and Retention

Security: We implement reasonable technical and organizational measures, including encryption of data in transit and at rest, designed to protect your information from unauthorized access, use, or disclosure. However, no system is 100% secure.

Data Breach Notification: In the event of a data breach involving personal information, we will notify affected Customers, regulators, and individuals as required by applicable law and within the legally required time.

Retention: We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, as directed by the Customer, and as required by law. Retention depends on the type of information, the Customer’s documented instructions, the sensitivity of the information, security and fraud risks, and legal requirements. After the applicable period, information is deleted or de-identified, subject to a limited period in encrypted backups and any legal preservation obligation.

Digital ID and mDL Data Retention: We retain digital-ID and mDL data in accordance with the Customer’s documented instructions, the period disclosed for the transaction, and applicable law. Before you approve a presentation, the transaction notice or the Customer’s privacy notice must state whether the data will be retained and the applicable retention period. At the end of that period, we delete or de-identify the data unless applicable law requires continued retention. We may delete it sooner in response to a lawful request, a Customer instruction, account closure, or a security need.

Biometric Data Retention: Notwithstanding the general retention policy, scans of facial geometry collected from End-Users are subject to a specific retention schedule. This biometric data will be permanently destroyed from our systems when it is no longer needed for the purposes of Verification and Fraud Prevention for which it was collected, or within a maximum of three (3) years from the date the initial biometric verification is processed by Trust Swiftly, whichever comes first. If a Customer closes their account with Trust Swiftly, all associated End-User biometric data is destroyed within ninety (90) days, unless legally required to retain it. This is subject to different requirements under applicable law or specific, lawful instructions from the data controller (our Customer).

7. Other Important Information

  • Children’s Information: Our Services are not directed to children under 13, and Customers may not use the Services to verify a child under 13 unless Trust Swiftly has agreed in writing to an appropriately configured use case and all required verifiable parental consent has been obtained. For individuals between 13 and the age at which they may consent under local law, the Customer is responsible for obtaining any required consent from a parent or guardian. Contact us if you believe a child’s information was submitted without proper authorization.
  • Supervisory Authority: If you are in the European Economic Area, UK, or Switzerland, you have the right to lodge a complaint with your local data protection authority if you believe our processing violates applicable law.
  • Changes to this Policy: We may revise this Privacy Policy from time to time. If we make material changes, we will notify you as required by law by posting the updated policy on our Site and revising the “Last Updated” date.

8. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact:

[email protected]

We have also appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. You can contact our DPO at: [email protected]