Biometric Data Retention & Destruction Policy

Fed Apps LLC (a Delaware company), operator of FreightBridge · Version 2026-06-21 · Effective June 21, 2026

This policy is published in accordance with the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and comparable state laws. It explains how FreightBridge, operated by Fed Apps LLC ("we," "us"), retains and permanently destroys biometric identifiers and biometric information.

1. What this covers

"Biometric data" means your facial-geometry scan ("face template"), the verification selfies from which it is derived, and the driver's-license (CDL) photograph used for comparison, together with information derived from them.

2. Why we collect it

We collect biometric data for the sole purposes of (a) verifying that you are the driver assigned to a load and detecting identity fraud and cargo theft at onboarding, pickup, transit, and delivery; and (b) supporting investigation and defense of claims, insurance matters, cargo theft cases, accidents, and legal proceedings related to loads verified on the platform. We do not use it for any other purpose.

3. Retention schedule

We retain biometric data only as long as reasonably necessary for the purposes above. We permanently destroy it at the earliest of: (a) two (2) years after your last identity verification on the platform; or (b) thirty (30) days after you withdraw consent or your account is deleted. Where the law of your state requires destruction sooner, that shorter period controls. We do not retain biometric data on the basis of mere app activity; the clock is tied to your last identity verification (or earlier resolution of the purpose).

4. Destruction method

"Permanent destruction" means irreversible deletion of the face template and the source images so that they cannot be recovered or regenerated. Destruction includes copies held by our processor (AWS Rekognition — including any face-collection entry) and copies in our routine backups, purged on our standard backup-expiry cycle. Deletion from Rekognition is performed using the service's provided APIs and controls.

5. Processors and disclosure

Facial matching and liveness detection are performed by AWS (Rekognition) acting solely as our service provider under a written data-protection agreement (Data Processing Addendum) that prohibits AWS from using, selling, or retaining your biometric data for its own purposes, or using it to train or improve any model. We have enabled AWS's AI Services Opt-Out Policy for these services. We do not sell, lease, trade, or otherwise profit from biometric data, and we do not disclose it except to the processor named above, anyone you separately authorize in writing, or as required by valid legal process. Biometric data is stored and processed in the United States.

6. Your rights

Withdraw consent anytime in the app at Settings → Privacy. To request access to, a copy of, or deletion of your biometric data, contact info@fedapps.org; we respond within 45 days. See our Privacy Policy for additional rights.

7. Changes

If we materially change this policy, we will publish the updated version with a new date and, where required, obtain renewed consent.

State-specific compliance notes

This policy is designed to satisfy the requirements of the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and the Washington Biometric Privacy Law.

Where any state law imposes a shorter retention period or additional requirement, that stricter rule applies to drivers subject to that law.

Contact

Fed Apps LLC (FreightBridge) · info@fedapps.org