This Privacy Policy explains how PASSID Ltd ("PASSID", "we", "us", "our") collects, uses, shares, and protects personal information when you use the PASSID mobile app, web app, websites, and APIs (together, the "Services"). PASSID is verification infrastructure — we help you prove verified financial and identity claims to institutions you choose. We are not a credit bureau, lender, bank, or decision engine; institutions make their own decisions.
PASSID Ltd is the data controller for personal information processed through the Services. Registered in England & Wales, 20 Farringdon Road, London EC1M 3HE. For any privacy question or to exercise your rights, contact our data protection team at security@passid.io.
This policy covers two groups of people: (a) individual users who create a PASSID to hold and share verified credentials, and (b) institution users who use PASSID to verify credentials. Where a section applies only to one group, we say so.
To issue a verified identity claim, we use our identity-verification partner Didit to perform government-ID and biometric verification. During this process the following may be collected and processed (by Didit on our behalf, and in part by us):
PASSID does not use your biometric data for surveillance, advertising, or any purpose other than verifying your identity. PASSID retains the result of verification (verified or not) and a one-way, hashed "identity fingerprint" derived from your document (used solely to enforce one-account-per-person and prevent fraud) — not your raw biometric images. Didit's processing of biometric data is governed by Didit's own privacy terms; see didit.me.
If you choose to connect a financial account, we use Plaid to securely link to your bank. PASSID never sees or stores your bank login credentials. With your permission, we access account and transaction information solely to compute verified claims (for example, income consistency, cashflow, or savings signals). Your raw transactions, balances, and statements are processed to derive these claims and are not shared with institutions — institutions receive only the resulting claims you authorise. Plaid's handling of your data is governed by Plaid's privacy policy.
For institution accounts we collect business contact details (name, work email, organisation, role), API keys and usage logs, billing information processed by our payment provider, and records of verification requests and outcomes.
We use personal information to:
This is the heart of PASSID. When you share, the institution receives only the verified claims you explicitly authorise — for example "identity verified: yes" or "income verified: yes" — scoped to the permissions and expiry you set. Institutions do not receive your raw bank data, transactions, statements, ID images, biometric data, or full national identifiers. You can revoke any active share at any time, which immediately prevents further access. We never sell your personal information.
Where UK or EU data protection law applies, we rely on: consent (for identity/biometric verification, connecting financial accounts, sharing claims, and non-essential cookies); performance of a contract (to provide the Services you request); legitimate interests (to secure the Services, prevent fraud, and improve our product, balanced against your rights); and legal obligation (for AML/KYC, tax, and other regulatory duties). You may withdraw consent at any time, without affecting processing already carried out.
We share information with trusted providers who process it only on our instructions and under contract:
We disclose personal information only: (a) to institutions you choose, limited to the claims you authorise (section 4); (b) to the service providers in section 6; (c) where required by law, regulation, legal process, or to protect the rights, safety, and security of users, the public, or PASSID; and (d) in connection with a merger, acquisition, or sale of assets, subject to this policy. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
We keep personal information only as long as necessary for the purposes above or as required by law:
When you delete your account, we delete or de-identify your personal information, except where we must retain certain records to comply with legal obligations or resolve disputes.
We use industry-standard technical and organisational safeguards, including: encryption in transit (TLS) and at rest; one-way hashing of passwords; signed, expiring authentication tokens; signed/verified webhooks; device binding; access controls on a least-privilege basis; and continuous logging and monitoring. No method of transmission or storage is perfectly secure, but we work continually to protect your information and to align our practices with recognised security standards.
PASSID supports cross-border financial trust, so your information may be processed in countries other than your own, including by the service providers in section 6. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised under applicable law.
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate data; delete your data; restrict or object to processing; port your data; and withdraw consent. You can also manage your active shares and connected accounts at any time within the app, and revoke any share immediately.
If you are in the EU/UK, these rights arise under the GDPR/UK GDPR. If you are a California resident, you have rights under the CCPA/CPRA, including to know, delete, and correct your information and to opt out of "sale"/"sharing" — note that PASSID does not sell your personal information or share it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights.
To exercise any right, contact security@passid.io. We may need to verify your identity before acting, and we will respond within the timeframe required by applicable law (generally 30–45 days).
We use cookies and similar technologies to operate the site, remember your choices, and understand usage. Non-essential analytics cookies load only with your consent via our cookie banner. You can change your choice at any time. See our Cookies Policy for details.
The Services are intended for adults (18+) and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
We may update this policy from time to time. We will update the "Last updated" date above and, where changes are material, provide additional notice. Your continued use of the Services after an update means you accept the revised policy.
For any privacy question, data request, or complaint, contact security@passid.io, or write to PASSID Ltd, 20 Farringdon Road, London EC1M 3HE. If you are in the UK/EU and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office, ico.org.uk).