Biometric Information Policy
Effective Date: December 1, 2025
This Biometric Information Policy describes how True Beauty Lashes, Inc. ("LashLovr," "we," "us," or "our") collects, uses, stores, and protects biometric data when you use our facial scan feature. This policy supplements our Privacy Policy and Terms of Conditions. By using the facial scan feature, you acknowledge that you have read and agree to the practices described here.
1. Overview and Applicable Laws Certain states in the U.S. have enacted specific laws governing the collection, use, storage, and disclosure of biometric data. These include the Illinois Biometric Information Privacy Act (740 ILCS § 14/1 et seq., "BIPA"), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001 et seq., "CUBI"), and similar laws in other states.
We define the following terms consistent with these laws:
- Biometric Identifier: A retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.
- Biometric Information: Any information based on a biometric identifier that is used to identify an individual.
- Biometric Data: Collectively refers to biometric identifiers and biometric information.
2. Biometric Data We Collect When you use our facial scan feature to receive personalized lash recommendations, we capture a single image of your face (focused on the eye area) via your device's camera. From this image, our AI model analyzes facial landmarks to derive eye shape attributes (such as size, spacing, depth, angle, proportion, and lid type).
We store the captured facial image along with the derived attributes. We do not collect or store retina or iris imagery, and we do not use the data to identify you in the real world outside of the LashLovr platform.
3. Purposes for Collecting and Using Biometric Data We collect and use biometric data solely for the following limited purposes:
- To provide you with accurate, personalized lash style recommendations and virtual try-on experiences.
- To review scan accuracy and improve our AI model's performance, particularly for diverse eye shapes and edge cases.
Your biometric data is not used for advertising, marketing to third parties, or any purpose unrelated to improving and delivering the LashLovr service.
4. How We Collect Biometric Data Biometric data is collected only when you actively initiate the facial scan feature and grant access to your device's camera. The process involves live processing with a single frame captured and transmitted securely to our servers.
5. Retention and Destruction of Biometric Data We retain biometric data only as long as necessary to fulfill the purposes described above. Specifically:
- Facial images and derived attributes are retained for no longer than three (3) years from your last interaction with the facial scan feature, or until you request deletion, whichever occurs first.
- Upon expiration of the retention period or at your request, we will permanently and securely delete your biometric data from our systems using industry-standard methods.
We do not retain biometric data longer than permitted or required under applicable law.
6. Security of Biometric Data We implement reasonable technical, administrative, and organizational safeguards to protect biometric data against unauthorized access, acquisition, loss, or misuse. These measures include:
- Encryption in transit (TLS 1.3) and at rest.
- Private storage buckets with strict access controls.
- Row-level security and role-based access policies.
- Time-limited signed URLs for any authorized internal access.
- Comprehensive input validation and rate limiting.
7. Disclosure of Biometric Data We do not sell, lease, trade, or otherwise profit from your biometric data. We will not disclose your biometric data to any third party except:
- To trusted service providers who assist us in operating the platform and are contractually obligated to protect the data and use it only for the purposes described in this policy.
- When required by applicable federal, state, or local law.
- In response to a valid court order, warrant, or subpoena.
8. Your Consent We collect, store, and use biometric data only with your explicit consent. Before you can use the facial scan feature, you will be presented with a clear notice and a link to this Biometric Information Policy. By checking the consent box and proceeding with the scan, you confirm that you have read, understood, and agree to the collection, use, storage, and retention practices described herein.
You may withdraw your consent at any time by deleting your account or requesting deletion of your biometric data (see Section 9).
9. Your Rights Regarding Biometric Data Depending on where you live, you may have specific rights regarding your biometric data, including:
- The right to know what biometric data we collect and how it is used.
- The right to access your biometric data.
- The right to request deletion of your biometric data.
- The right to opt out of certain uses or disclosures (where applicable).
Illinois residents may refer to BIPA, Texas residents may refer to CUBI, and California residents may exercise rights related to sensitive personal information under the CCPA. Residents of other states should review their state's applicable privacy laws.
To exercise any of these rights, contact us using the information in Section 10.
10. Contact Us If you have questions about this policy, our biometric practices, or to submit a data access or deletion request, please contact: hello@truebeautycorporate.com.
11. Changes to This Policy We may update this policy from time to time to reflect changes in our practices or legal requirements. Material changes will be posted on our website and app, and we will notify users through appropriate channels. Your continued use of the facial scan feature after changes take effect constitutes acceptance of the updated policy.


