Skip to content
Legal

Privacy Policy

Effective Date: July 20, 2026 · Last Updated: July 20, 2026

1. Introduction

This Privacy Policy ("Policy") describes how PassportSnap ("we," "us," or "our") handles information when you visit passport-snap.com (the "Site") and use our browser-based passport and ID photo processing tool (the "Service"). This Policy is designed to comply with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Children's Online Privacy Protection Act (COPPA), the Federal Trade Commission Act (FTC Act), and the General Data Protection Regulation (GDPR) for users in the European Economic Area.

By accessing or using the Site, you represent that you are at least 18 years of age (or the age of legal majority in your jurisdiction) and have the legal capacity to enter into binding agreements. If you are using the Service on behalf of another individual (e.g., a family member), you represent that you have their explicit consent and legal authority to submit their photograph. If you do not agree to this Policy, do not use the Service.

2. Client-Side Processing Architecture

The Service is architected as a fully client-side application. All image processing — including upload, decoding, cropping, background isolation, face-geometry analysis, and export — executes entirely within your web browser using the HTML Canvas API and WebAssembly (WASM). All operations are deterministic image processing.

  • No image is ever transmitted to a server. Your photo never leaves your device. There is no upload endpoint, no cloud storage, and no server-side processing pipeline.
  • No biometric templates are created or stored. Face-geometry landmarks are computed in real time for auto-alignment and photo review, then discarded when you close the browser tab.
  • No face embeddings are extracted or persisted. The Service does not build, store, or transmit any facial-recognition model, face embedding, or biometric identifier as defined under 815 ILCS 42/, Texas Bus. & Com. Code 503.001, or Cal. Civ. Code 1798.140(b).
  • All processing terminates when you close the tab. No image data survives a session. There is no background job, no queued deletion, and no retention period — because nothing is retained.

3. Photo Ownership and Representation Warranty

By uploading a photograph to the Service, you represent and warrant that:

  • Own likeness or authorized consent: The photograph depicts your own true likeness, or you have obtained explicit, informed, written consent from the individual depicted (or their legal guardian if the individual is a minor) to submit the photograph for the application you are preparing.
  • Legal authority: You have the legal authority to submit the photograph for the stated purpose under the laws of your jurisdiction.
  • No alteration: The photograph has not been digitally altered, generated, or manipulated in any way that changes the depicted individual's appearance prior to processing by the Service.
  • Recency: The photograph was taken within the time period required by the applicable issuing authority (typically within the last 6 months).

PassportSnap has no ability to verify photo ownership or consent. The legal responsibility for photo authenticity and authorization rests entirely with the user. PassportSnap disclaims all liability for any legal consequences arising from the submission of photographs that do not comply with this warranty.

4. Information We Do Not Collect

Because the Service runs entirely in your browser, we do not collect, store, process, or have access to any of the following:

  • Uploaded photographs or cropped output images
  • Facial geometry data, face embeddings, or biometric identifiers
  • Account credentials, email addresses, names, or phone numbers
  • Payment or billing information
  • Analytics events, behavioral data, or usage telemetry
  • Cookies, local storage items, or persistent device identifiers
  • Geolocation data

5. Server Log Files and Technical Data

Our hosting infrastructure (Cloudflare Pages) automatically logs standard HTTP request data when you access the Site. These logs may include:

  • IP address of your connecting device
  • Date and time of each request
  • Browser type, user-agent string, and HTTP status code
  • Requested resource (URL path)

Purpose: These logs are used exclusively for infrastructure security, denial-of-service mitigation, and aggregate traffic analysis. They are not linked to any uploaded image or biometric data. Our systems cannot associate an IP address in a log file with any specific face or processed photo.

Retention: Server logs are retained for a maximum of 12 months and then automatically purged. We do not sell, share, or monetize server log data.

6. Biometric Data Disclosure (BIPA / CUBI / FTC)

The Service performs real-time face-geometry analysis using on-device algorithmic processing to detect facial landmarks for auto-centering, roll correction, and photo-review guidance (e.g., glasses detection, head-pose checks). This processing occurs entirely on-device and the landmark data is discarded when the session ends.

Illinois BIPA Compliance (815 ILCS 42/)

Under the Illinois Biometric Information Privacy Act, "biometric identifier" includes "scan of hand or face geometry" but explicitly excludes "photographs." Because the Service:

  • Processes photographs (not raw biometric scans)
  • Does not create face embeddings or persistent biometric templates
  • Does not store, transmit, or sell any biometric data
  • Does not identify or authenticate individuals

...the Service falls outside the definition of "biometric identifier" under BIPA. We do not collect written consent for biometric data because no biometric data is collected, stored, or transmitted.

Texas CUBI Compliance (Bus. & Com. Code 503.001)

Texas law defines "biometric identifier" similarly to BIPA and also excludes photographs. The same analysis applies: the Service processes photographs, does not extract or store biometric templates, and therefore does not collect "biometric identifiers" under Texas law.

FTC Section 5 Compliance

Per the FTC's 2023 Policy Statement on Biometric Information, we do not make false or unsubstantiated claims about the accuracy or fairness of our face-geometry analysis. The on-device analysis provides advisory photo-review observations only — it does not guarantee passport acceptance.

7. California Consumer Privacy Act (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act of 2018 (Cal. Civ. Code 1798.100 et seq.), as amended by the California Privacy Rights Act (CPRA), grants you additional rights.

Categories of Personal Information Collected

We do not collect any "personal information" as defined under CCPA 1798.140(v). Specifically, we do not collect:

  • Identifiers (name, email, address, IP — IP appears only in server logs not linked to identity)
  • Personal information described in Cal. Civ. Code 1798.80(e)
  • Protected classification characteristics
  • Biometric information (Cal. Civ. Code 1798.140(b))
  • Internet or electronic network activity
  • Geolocation data
  • Inferences drawn from any of the above

CCPA Consumer Rights

California residents have the right to:

  • Right to Know (1798.100): Request disclosure of personal information collected. We collect none.
  • Right to Delete (1798.105): Request deletion of personal information. We retain none.
  • Right to Correct (1798.106): Request correction of inaccurate personal information. We maintain none.
  • Right to Opt-Out of Sale/Sharing (1798.120): We do not sell or share personal information.
  • Right to Limit Use of Sensitive Personal Information (1798.121): We do not use or disclose sensitive personal information.
  • Right to Non-Discrimination (1798.125): We do not discriminate against you for exercising any CCPA right.

Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) signal as a valid opt-out of sale/sharing under CCPA 11 CCR 7025(c)(6). When we detect the Sec-GPC: 1 header or navigator.globalPrivacyControl, we treat it as an opt-out.

8. Other US State Privacy Laws

As of July 2026, twenty US states have comprehensive consumer privacy laws in effect, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon (OCPA), Montana (MCDPA), Florida (FDBR), Iowa (ICDPA), Delaware (DPDPA), New Hampshire (NH SB 255), Nebraska (NDPA), New Jersey (NJ SB 332), Tennessee (TIPA), Minnesota (MCDPA), Maryland (MODPA), Indiana (ICDPA), Kentucky (KCDPA), and Rhode Island (RIDTPPA).

Because the Service collects no personal information — no biometric data, no identifiers, no behavioral data — it does not trigger the applicability thresholds of any of these laws. We nevertheless maintain compliance-ready disclosures as a precautionary measure.

9. Children's Privacy (COPPA)

The Service is not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. Under the Children's Online Privacy Protection Act (15 U.S.C. 6501 et seq.), we are not required to obtain verifiable parental consent because we do not collect any personal information from any user, regardless of age.

If we become aware that a child under 13 has used the Service, we will not retain any data because no data is retained by design.

10. Authorized Use Only

PassportSnap is a photo-formatting tool. Use it to prepare your own passport or ID photo, or a photo you are authorized to submit on another person's behalf with their explicit consent.

The photo you submit must be a truthful representation of the person in the application. Do not use PassportSnap for any fraudulent purpose, including misrepresenting identity in an official application.

  • You are responsible for complying with the rules of the authority you are applying to, including any current photo requirements.
  • Misusing a photo in an identity document application is unlawful in most countries. You are responsible for understanding and complying with the laws of the jurisdiction where you use the exported photo.

11. Photo Review Guidance & Disclaimer

PassportSnap provides framing and photo-review guidance based on country-specific photo guidelines. It is a photo-formatting tool, not a government agency or authorized passport processor.

  • We do not guarantee that any photo produced by the Service will be accepted by any issuing authority.
  • You are responsible for verifying the current requirements of the authority you are submitting to.
  • The Service is provided "as is," without warranty of acceptance, fitness, or result. You use the Service, and submit any output you produce, entirely at your own risk.
  • The Service does not perform automated face manipulation, skin smoothing, beauty filtering, teeth whitening, face slimming, or any alteration that changes your appearance. All processing is deterministic image processing: cropping, background standardization, DPI adjustment, and minor exposure correction.

12. Third-Party Services and Hosting

The Site is hosted on Cloudflare Pages, a static-site hosting platform. Cloudflare may collect standard technical data (IP address, browser type, request timestamps) as part of its content delivery and security infrastructure. This data is governed by Cloudflare's own privacy policy and is not used by PassportSnap for any purpose beyond site delivery.

The Service uses the following client-side libraries, all of which execute within your browser and do not transmit data to external servers:

  • An on-device face-geometry analysis package — used for face landmark detection, auto-centering, roll correction, and photo review. Its model files are loaded from /public/ and cached by your browser.
  • An on-device background isolation routine — used to standardize the photo background. Its model files are loaded from /public/ and run entirely in-browser via WebAssembly.
  • jsPDF — Client-side PDF generation for print sheets. No data is transmitted.

13. Data Security

Because no personal information or image data is transmitted to or stored on our servers, the primary security measure is the architectural decision to keep all sensitive processing on-device. We additionally maintain:

  • HTTPS encryption for all Site traffic (TLS 1.3)
  • No server-side image storage — there is nothing to breach
  • No database of user information — there is nothing to exfiltrate
  • Cloudflare DDoS protection and Web Application Firewall

14. Cookies and Tracking Technologies

We do not use persistent cookies, advertising pixels, cross-site tracking, or behavioral analytics. The Service does not use Google Analytics, Facebook Pixel, or any other third-party tracking service. If your browser is configured to reject cookies, the Site will function normally, but certain browser-level features (e.g., service worker caching) may be affected.

15. Data Sharing, Transfers, and Indemnification

We do not sell, rent, lease, license, or share any personal information with third parties, advertisers, data brokers, or analytics providers. We have no personal information to share. Image data is never transmitted outside your browser.

In the event we receive a valid legal process (subpoena, court order, or warrant), we would only be able to produce server log data (IP addresses, timestamps), which cannot be linked to any specific image or face. We will notify you of any such request unless legally prohibited from doing so.

15.1 Indemnification

You agree to indemnify, defend, and hold harmless PassportSnap, its operators, and affiliates from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or in connection with:

  • Your use of the Service to process a photograph that does not depict your own likeness, or for which you did not obtain the depicted individual's informed consent
  • Any claim by a third party that the photograph you submitted was used without their authorization
  • Any violation of applicable laws, regulations, or government requirements related to your use of the Service or submission of photos to issuing authorities
  • Any false, misleading, or fraudulent representation made in connection with your use of the Service

16. International Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) may apply to your use of the Service. Under GDPR:

  • Legal Basis: Our legal basis for processing is legitimate interest (Art. 6(1)(f)) in providing a secure, private photo-formatting tool, combined with your explicit consent obtained via the privacy-policy checkbox before uploading.
  • Data Controller: PassportSnap Administration, [email protected]
  • Data Processing: All image processing occurs on your device. No image data is transferred to or processed by us or any third-party processor.
  • Data Transfers: Cloudflare Pages may process standard HTTP logs in the US. This transfer is covered by Cloudflare's EU Standard Contractual Clauses (SCCs).
  • Data Subject Rights: You have the right to access, rectify, erase, restrict processing, and port your personal data. Since we collect no personal data, these rights are satisfied by the zero-collection architecture.
  • Right to Withdraw Consent: You may withdraw consent at any time by closing the browser tab, which immediately terminates all processing and discards all data.
  • Data Protection Impact Assessment: We have assessed that the zero-collection, client-side-only architecture presents minimal risk to data subjects. No DPIA is required.

17. Do Not Track and Global Privacy Control

We honor the Global Privacy Control (GPC) signal as a valid opt-out of sale/sharing under CCPA and equivalent state laws. Twelve US states currently require businesses to honor GPC: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. We recognize and comply with this signal universally.

18. Changes to This Policy

We may update this Policy from time to time. The "Last Updated" date at the top of this page reflects the most recent revision. Material changes will be posted on this page. Continued use of the Service after changes are posted constitutes your acceptance of the revised Policy.

19. Contact Information

For legal inquiries, privacy requests, or general questions about this Policy:

  • Entity: PassportSnap Administration
  • Email: [email protected]
  • Website: passport-snap.com

If you are a California resident and wish to exercise your CCPA rights, please contact us at the email above. We will respond within 45 days as required by law.

20. Effective Date and Jurisdiction

This Policy is effective as of July 20, 2026. This Policy is governed by the laws of the United States and, where applicable, the state laws referenced herein. Any disputes arising from this Policy shall be resolved in the courts of competent jurisdiction in the United States.

— End of Privacy Policy —