Biometric Data Policy
Effective Date: August 13, 2026 · Version 1.5
Nero Media Group, Inc. (“Nero,” “we,” “us,” or “our”) operates the Guestlist platform and services (“Guestlist”), a photo-matching service that uses facial recognition technology. This Biometric Data Policy explains how we collect, use, store, and destroy biometric identifiers and biometric information as defined under applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14) (“BIPA”).
1. What We Collect
When you voluntarily submit a selfie photograph through our platform, we use Amazon Web Services Rekognition (“AWS Rekognition”) to generate a mathematical representation (a “face vector” or “face template”) of your facial geometry. This face vector constitutes a biometric identifier.
Specifically, we collect and process:
- Selfie photograph — the image you submit, stored in private cloud storage and used only for face-matching operations.
- Selfie facial geometry vector — computed transiently each time a match is performed. It is used for the comparison and discarded; it is never stored in any persistent collection.
- Event-photo face templates — facial geometry detected in event photographs uploaded by the event organizer, indexed into a collection specific to that event so your selfie can be matched against it.
2. Purpose of Collection
We collect biometric data for the following purposes:
- Photo matching: Matching your selfie to event photographs taken at events you attended, allowing us to identify and present photos of you in your personalized gallery.
Face matching is private. Photos matched to you are shown only to you, in your own gallery view. We do not display your name on photographs to other guests.
We do not use biometric data for surveillance, advertising, profiling, identifying you to other people, or any purpose other than helping you find photographs of yourself.
3. How We Process Biometric Data
- Face matching is only active for an event when the event organizer has expressly enabled it for that event.
- Your selfie is sent to AWS Rekognition, a third-party facial recognition service operated by Amazon Web Services, Inc.
- AWS Rekognition computes your selfie's face vector transiently and compares it against face templates already indexed from that event's photographs to find matches. The selfie vector is not retained after the comparison.
- Your selfie image is stored in our secure private cloud storage (Supabase Storage, hosted on AWS) and is used only for face-matching operations. It is never displayed to other users.
- Face templates from event photographs are stored within AWS Rekognition collections that are specific to each event.
4. Informed Consent
We will not collect or process your selfie, or link any biometric data to your identity, without first providing you with written notice and receiving your informed, written consent. Separately, when an event organizer enables face matching for an event, facial geometry is detected in that event's photographs — including the faces of people who have not used our platform — solely so that consenting guests can find their own photos. These photo-derived templates are linked to photos, not to any person's identity, and are destroyed as described in the Data Destruction section below. The event organizer is responsible for providing notice of face matching at their event where required by applicable law (see Section 5).
Before your selfie is processed, you will be presented with a consent screen that discloses:
- The specific biometric data being collected;
- The purpose and duration of the collection;
- The third-party processor (AWS Rekognition) involved;
- A link to this Biometric Data Policy for your review.
You must affirmatively consent (by checking an unchecked checkbox and providing your electronic signature) before any biometric processing occurs. Consent is entirely voluntary — you may use our platform without facial recognition features by declining consent.
Facial recognition features are only available to users who confirm they are 18 years of age or older. We verify age from your date of birth and store only the resulting confirmation; we do not process biometric data for anyone who has not confirmed they are an adult.
5. People in Photos Who Do Not Use Guestlist
Event photographs often include people who never create a Guestlist account. If the event organizer has enabled face matching, facial geometry is detected for the faces in those photographs so that matching can work. For anyone who has not submitted a selfie and consented:
- No identity is attached to their face template — it exists only as a property of the photograph, and we have no way to know whose face it is;
- Their face is never searched for, tagged, or surfaced to anyone;
- Their templates are destroyed on the same schedule as all event-photo templates (see Data Destruction below);
- The event organizer is responsible for providing notice at their event that face matching is in use, where applicable law requires it. To have a photograph of you removed from an event gallery, contact the event organizer or contact us at the address in this policy.
6. Disclosure to Third Parties
We will not sell, lease, trade, or otherwise profit from your biometric data. We do not disclose biometric data to any third party except:
- AWS Rekognition — for the sole purpose of performing facial recognition matching as described above; and
- When disclosure is required by law, legal process, or court order.
7. Retention Schedule
We retain biometric data only until the purpose it was collected for — helping you find photographs of yourself — has been satisfied, and never longer than twelve (12) months, whichever occurs first. For your selfie and its associated biometric data, the twelve months run from your Last Face Matching Activity (defined below); for an event's face templates, from the event's date. Both bounds are enforced by an automated daily process and do not depend on anyone remembering to delete an event. Destruction happens earlier when any of the following occurs (whichever comes first):
- You withdraw consent in Settings — your selfie and your face templates are deleted immediately;
- You delete your account or request deletion of your data;
- For event-photo face templates: the underlying photo is deleted or hidden, the event is deleted, or the event organizer disables face matching for the event — the event's face-template collection is destroyed.
“Last Face Matching Activity” means the most recent date on which Face Matching successfully ran for you in any gallery — when you set it up, retake your selfie, join a gallery with Face Matching, or open a gallery where new photos were added since your last match. If no such activity is recorded, we use the date of your biometric consent, and then your most recent account activity, whichever is available.
8. Data Destruction
Upon expiration of the retention period, or upon receiving a valid deletion request, we will permanently destroy your biometric data using the following methods:
- Selfie photograph: Permanently deleted from our cloud storage (Supabase Storage / AWS S3).
- Face vectors: Your selfie-derived face vector is used transiently for matching and is not stored in any persistent Rekognition collection. Event-photo face templates remain associated with event photos (not individual users) and are destroyed when the photo or event is deleted, or when the event organizer disables face matching for the event.
- Consent records: Consent audit logs are retained for legal compliance purposes but are marked as revoked and no longer authorize any processing.
9. Data Security
We protect your biometric data using industry-standard security measures, including:
- Encryption in transit (TLS/HTTPS) for all data transmissions;
- Encryption at rest for stored selfies and associated data;
- Access controls limiting biometric data access to authorized systems and personnel;
- Secure, audited cloud infrastructure (AWS, Supabase hosted on AWS);
- Regular review of security practices and third-party processor compliance.
Our security measures are at least as protective as those used for other confidential and sensitive information we maintain.
10. Your Rights
You have the right to:
- Withdraw consent at any time — without deleting your account — using “Delete my selfie & withdraw consent” in your account settings. This immediately deletes your selfie and removes every photo tag created by face matching;
- Request deletion of your biometric data by contacting us or using the “Delete My Account” feature;
- Decline biometric collection — face matching is opt-in; you can browse, save, and favorite photos without ever taking a selfie;
- Access information about what biometric data we hold about you by contacting us.
11. Contact Information
If you have questions about this Biometric Data Policy or wish to exercise any of your rights, please contact us at:
Guestlist is a service operated by Nero Media Group, Inc.
Email: ontheguestlistapp@gmail.com
12. Changes to This Policy
We may update this Biometric Data Policy from time to time. If we make material changes to how we collect, use, or share biometric data, we will notify you through the platform and request new consent as required by law. The “Version” number at the top of this document will be updated with each revision.
See also: Privacy Policy · Terms of Service · Cookie Policy