Last Updated: August 4, 2026
Greetings from Jumio Corporation!
This Privacy Notice (“Notice”) describes the privacy practices of Jumio Corporation (“Jumio,” “us,” or “we”) concerning personal information collected in connection with Jumio’s provision of verification, authentication, and related online services (the “Services”).
This Notice provides information about the personal information collected through the Services. The scope of your consent is described in Section 12 (“Your consent”).
Our Website Privacy Notice describes our privacy practices in connection with our website and Customer portals. For individuals protected by the Washington State My Health, My Data Act, please see our Washington State Consumer Health Privacy Notice.
| Important note: Jumio makes the Services available to our Customers (as defined below) for integration into their websites and mobile applications. For certain Customers (including some in the EEA/UK), Jumio serves as a “processor” (or “service provider”). Please begin with the Customer with which you have an existing relationship for information about your privacy rights. |
Jumio is headquartered in Sunnyvale, California and has offices and Customers around the world. We help third-party businesses (“Customers”) prevent fraud, verify the identity of their users (“you” or “End Users”), and protect the integrity of End User accounts. Jumio uses information about you to provide and improve these Services or develop new services for similar purposes. We analyze the collected data and pass along risk signals to our Customers to warn them about potential risks associated with their End User transactions and accounts.
Please note: we do not sell, share, or otherwise use your personal information for cross-contextual behavioral advertising.
Data protection and privacy laws in certain jurisdictions differentiate between “controllers” (or “businesses”) and “processors” (or “service providers”).
This Notice generally describes Jumio’s privacy practices as a Controller. While providing your personal information is voluntary, we may not be able to provide our Services to our Customers without it.
Jumio provides an integrated identity verification, authentication, and fraud prevention Service to its Customers. This Service enables our Customers to verify their End Users’ identities by processing personal information (see Section 5) to assess the authenticity of identity information and detect potentially fraudulent activity.
As part of this Service, we collect, analyze, and retain personal information collected in connection with transactions on an ad–hoc and an ongoing basis provided by or on behalf of our Customers and their End Users, including information contained in government-issued identification documents and facial images. These processing activities may be performed in an automated manner and include comparing personal information with data previously processed as part of the Service and matching an image of your face with the image contained on your identification document in order to verify identity and identify patterns indicative of fraud.
Jumio is committed to constantly improving its service in order to help its Customers manage evolving fraud risks. Therefore, the Service entails incremental improvement of the service making use of new technological innovations as they become practical to implement.
As part of its service to our Customers, Jumio shares the results of these analyses, as well as relevant personal information (such as identification document data and facial images), with our Customer with whom you have engaged or intend to engage, as well as with Jumio’s service providers acting on its behalf.
Jumio may obtain your personal information from the following sources:
If you use Jumio’s Authentication service, we may install service workers on your device to speed up subsequent verifications. These do not collect any information about you and do not track you. We may also use cookies in connection with the Services, which you can learn about by visiting our Cookie Notice.
For the purposes described in Section 6, Jumio may process the following information:
Biometric DataJumio’s collection of personal information may include data that may be considered biometric data in some jurisdictions. We will collect this information via facial recognition or similar technology from an image (e.g., a selfie) or video (including audio), and from an image of your face as it appears on an identification document that you provide. We may share such data with a Customer with which you have a direct relationship and with our service providers. Jumio may collect, process, re-collect, regenerate, otherwise obtain, and store such data for the purpose of providing and improving its Services, and for the long-term proof of inspection of your provided form of identification. Jumio will permanently destroy such biometric data derived from images and recordings in its possession within three years, except where a shorter period is required by law after you first provided those images or videos. Where Jumio serves as a processor (or service provider), we will permanently destroy any such biometric data in our possession in accordance with the Customer’s instructions but no longer than the earlier of the date (i) that the Customer ceases to have a relationship with Jumio or (ii) that is within three years, except where a shorter period is required by law, after the date that the Customer informs Jumio its last interaction with you has occurred. |
We process the personal information described in Section 5 for the following purposes:
We may also process the personal information listed in Section 5 to:
We may, for the purposes described in this Section 6, use artificial intelligence tools in line with applicable AI regulations of your jurisdiction.
Jumio may disclose your personal information to the following types of recipients and in the following types of scenarios:
If you require further information on the recipients of your personal information, a list of the third parties with whom we may share your personal information can be made available upon request via the contact details provided in Section 16.
Information for California residents. Other than with your consent, Jumio does not sell or share your personal information. The terms “sell,” “share,” and “personal information” are defined by the California Consumer Privacy Act (the “CCPA”) and the California Privacy Rights Act (“CPRA”).
Except as otherwise provided in this Notice, we retain personal information for as long as necessary to: (i) fulfill the purposes outlined in Section 6, (ii) comply with legal obligations, or (iii) defend against potential legal claims.
Where Jumio is a processor (or service provider), we retain personal information only as instructed by the Customer.
If you require further information on the retention periods regarding the processing of your personal information, they are accessible upon request via the contact details provided in Section 16.
Your personal information may be transferred to and processed in the United States for the purposes described in Section 6. The recipients described in Section 7 may process personal information in countries other than your country of residence. The data protection laws in these countries may be different from, or less stringent than, those in your country of residence. We take measures to help protect your personal information when it is transferred from the European Economic Area (“EEA”), Switzerland, the United Kingdom (“UK”), or Brazil to other countries. We may rely on adequacy decisions for certain countries, or include standard contractual clauses in our contracts with recipients which are accessible upon request via the contact details provided in Section 16.
We use commercially reasonable safeguards designed to protect your personal information against loss or unauthorized access, use, modification, or deletion. However, no security program is foolproof, and thus we cannot guarantee absolute security. For more details, please visit our Security page.
Depending on your location, you may have the right to:
To exercise these rights, please email [email protected]. We may need to verify your identity first, and if we deny a request, you may have the right to appeal by sending an email to the same address. We will not discriminate against you for exercising any of the above rights.
Where we process your personal information based on your consent, you may withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
When you provide your consent to us, you are consenting to Jumio obtaining and using your personal information (see Section 5) to enable our provision of the Services to our Customers (see Section 3), which may include the processing of special categories of personal information (e.g. biometric data) and is partly based on machine learning and facial recognition algorithms.
You may withdraw your consent at any time. The withdrawal of your consent does not affect the lawfulness of processing based on your consent before its withdrawal. If Jumio has collected your personal information on the basis of your consent and you then withdraw your consent, Jumio may retain your personal information independent of your consent as permitted by applicable law and to the extent necessary to establish, exercise or defend legal claims, to comply with legal obligations, or to identify potentially fraudulent transactions.
In certain circumstances, to properly verify End Users’ identification and for fraud prevention purposes, Jumio may process and share the following information with Idwall, a third-party service provider for fraud prevention acting as an independent data controller as defined by applicable law:
For this processing activity, Jumio will not share or disclose any Biometric Data. Please refer to Idwall’s Privacy Policy for more information about your privacy rights, retention, and how your personal information is used and shared.
Jumio’s Data Protection Officer and Person in Charge (“Encarregado”), Joe Kaufmann, may be contacted at [email protected].
Jumio’s Services are not directed to children under the age of 13, and Jumio will never knowingly collect information from anyone it knows is under the age of 13. We recommend that persons over 13, but under 18 years of age, ask their parents for permission before engaging with the Services or sending any information about themselves to anyone over the Internet.
To help safeguard the quality of the data provided by the Services, Jumio implements measures such as machine learning capabilities or manual review by specially trained verification agents. When we process the personal information automatically, we apply the following examples of criteria:
Jumio uses these automated checks to inform our Customer, but Jumio does not use automated decision-making to make a final decision that would produce legal or similarly significant effects for you. Please contact the Customer directly with any questions regarding the rights you may have to the extent your personal information is subject to automated decision-making.
When we process personal information as a processor (or service provider) for our Customers, we are acting on their behalf. When we process personal information of residents of the EEA, Switzerland, the UK, or Brazil as a controller (or business), we will do so with the following legal bases:
We may update this Notice as we make changes to the Services in the future. We recommend reviewing this page periodically for any updates. Notice of material changes will be provided appropriately.
Data Protection Officer: [email protected].
Mail: Jumio Corporation ATTN: Privacy | 100 Mathilda Place, Suite 100 | Sunnyvale, CA, 94086 U.S.A.
EU Representative: Jumio Software Development GmbH, Lunaplatz 5, 4030 Linz, Austria.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.trustarc.com/watchdog/request.