stile

Privacy Notice

How Stile handles verification data, merchant account data, retention, and requests. This notice is factual product guidance for review, not a substitute for legal advice.

Session create, capture and verify, then a signed webhook result

Last updated: September 24, 2026.

What this notice covers

This notice explains how Stile handles personal data for the public website, merchant account evaluation, and identity or age verification workflows. Stile is an identity-verification API for regulated commerce. Merchants configure the verification flow they need, and Stile returns a signed webhook with the eligibility decision, session ID, and audit pointer.

This page is written for users, merchants, and reviewers who need the practical data-handling shape. Contract terms, data-processing terms, and customer-specific retention settings are handled in the applicable agreement with each merchant.

Data Stile may collect

Depending on how you interact with Stile, we may process these categories of data:

  • Verification data: document images, selfie or liveness captures, barcode or OCR outputs, mobile driver's license attributes, jurisdiction, age tier, verification result, session ID, and audit pointer.

  • Biometric data: face-match and liveness signals generated during verification. These are used to confirm that the document presenter is present and matches the credential portrait.

  • Merchant and account data: work email, company, role, requested product interest, support messages, account configuration, API usage, webhook configuration, and billing or procurement context.

  • Contact and messaging data: phone number, records of customer-obtained prior permission, SMS delivery metadata, and STOP or HELP responses when Stile sends one-time transactional verification links.

  • Technical data: IP address, device and browser information, logs, security events, analytics events, and diagnostic data needed to operate and secure the service.

How Stile uses data

Stile uses data to provide, secure, and improve verification workflows. That includes:

  • creating and running verification sessions;

  • performing document checks, OCR, barcode cross-reference, liveness, face match, mobile driver's license attribute checks, age-tier resolution, and jurisdiction handling;

  • returning a signed eligibility webhook and session-level audit pointer to the merchant;

  • sending one transactional SMS with a secure verification link after a business customer has obtained the known recipient's prior permission for that request;

  • preventing fraud, debugging reliability issues, and maintaining security logs;

  • responding to support, sales, procurement, and compliance review requests.

What merchants receive

In the default configuration, the merchant's product code receives the signed webhook with the eligibility decision, jurisdiction or age tier when configured, and a session ID. The merchant does not receive raw document fields, biometric templates, date of birth, or source images by default. Configurations that surface specific document fields to the merchant are available only when a verification flow explicitly requires them and are documented per merchant during onboarding.

Some verification flows use selfie, liveness, and face-match signals. Stile uses those signals to verify that the person completing the flow is present and matches the credential being checked. Where notice, consent, or a written release is required, the merchant's implementation and Stile's hosted verification flow should present the required disclosures before biometric processing starts.

Stile does not sell biometric data. Biometric templates and source images follow the retention setting configured for the merchant account or session, as described below.

Retention and deletion

Retention is configurable per account. The default is delete-on-completion: source images and biometric templates are discarded once the verification session resolves and the signed webhook is delivered. Merchants who need lookback for chargeback dispute resolution or fraud-investigation review can configure a retention window measured in days and bound to their contractual obligations.

The eligibility signal, session ID, webhook event, and audit pointer may be retained on a longer horizon to support audit trails, dispute review, security, and legal obligations. The underlying document and biometric artifacts are not retained longer than the configured retention policy unless a legal hold or similar obligation applies.

Sharing and subprocessors

Stile shares data with service providers that help operate the product, including infrastructure, storage, email, security, support, and verification-processing providers. Those providers process data for Stile's service operations under the applicable agreements. Public website analytics and company-identification recipients are described separately below. Stile may also disclose data when required by law, to protect the service, or as part of a business transaction subject to appropriate safeguards.

All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.

Website and dashboard analytics, cookies, and your choices

Stile may use PostHog to understand how eligible visitors use stile.id, docs.stile.id, and dashboard.stile.id, and to improve signup, onboarding, and product workflows. When event analytics runs, Stile sends a reviewed set of event names and limited metadata, such as a route category, action type, placement, counts, and pseudonymous identifiers. The event payload does not include form contents, submitted email addresses, documentation search terms, copied code, credentials, or raw customer content. PostHog receives the request IP address and user agent at its US-hosted service; Stile enables IP anonymization for subsequent processing.

Stile may use Google Analytics on stile.id and docs.stile.id to measure visits to public page categories. Google receives pseudonymous browser and session identifiers, cookie information, browser and device metadata, and the request IP address. Stile supplies a page category instead of the full page URL and excludes form contents, submitted email addresses, search terms, copied code, URL query strings, fragments, and the referring page URL from this integration. Advertising personalization, Google signals, user-provided data collection, and Enhanced Measurement are disabled.

Stile may use Apollo to identify the company associated with an eligible public website or documentation visit. Apollo receives the request IP address, a pseudonymous browser identifier stored in the browser, and the visited page category. Company identification is not anonymous. Stile uses Company-only mode, with person-level identification disabled, and does not run Apollo in the dashboard or verification flows. Apollo may act as an independent controller for information covered by its own privacy policy and terms; it is not represented here as solely a service provider.

For US visitors, public event analytics and company identification may run by default after the privacy service confirms eligibility. Outside the US, they remain off until you explicitly accept the relevant categories. You can allow analytics without allowing company identification, or opt out of all optional tracking in Privacy Choices. We honor Global Privacy Control as an opt-out. Dashboard event analytics uses PostHog only, with US opt-out and explicit opt-in outside the US. Unknown geography or a privacy-service failure leaves optional tracking off. Withdrawing stops new collection and cancels pending work where it has not already been delivered; it cannot recall information already received by a provider.

Under PostHog's current Startup plan, event data is covered by a seven-year retention term. Google Analytics is configured to retain event-level data for two months and user data for fourteen months, with the user-data period restarting on new activity. These Google settings do not limit aggregate standard reports. Apollo's published policy describes retention based on processing purposes, legal requirements, and deletion requests rather than one fixed visitor-data period. You can submit a privacy or deletion request to Stile through the contact page and to Apollo through its Privacy Center.

Google and Apollo may process information in the United States and other countries described in their privacy terms. For Apollo's processing, retention and privacy-request options, see https://www.apollo.io/privacy-policy. Optional Vercel measurement remains off.

Optional session recording captures a masked representation of reviewed website, documentation, and dashboard pages, together with navigation, clicks, and scrolling. Inputs and sensitive areas are masked or excluded. Forms, verification content, embedded frames, media, credential-management pages, and other excluded dashboard routes are not recorded. Console logs, network request bodies and headers, canvas content, and keystrokes are not captured.

Session recording has a separate privacy choice. For US visitors without a saved privacy choice, it may run after the privacy service confirms eligibility. Outside the US, it stays off until you explicitly allow recording. Existing analytics choices do not automatically allow recording. Global Privacy Control and opting out stop new collection and discard unsent recording data; they cannot recall data already delivered.

Recording is configured for 100% of eligible sessions, with new recordings configured for 30-day retention in PostHog. Temporary recording identifiers remain in browser memory and are cleared on opt-out, excluded routes, account or workspace changes, and page exit. They are not taken from consent records or submitted contact details.

Your privacy choices and requests

Depending on your location, you may have rights to request access, correction, deletion, portability, objection, restriction, or opt-out of certain processing. Verification requests are often tied to a merchant relationship, so Stile may need to coordinate with the merchant that initiated the session before completing a request.

To make a privacy request, contact Stile through the contact page and include enough context to locate the relevant account or verification session. Do not send government ID images or biometric data through the contact form.

Security posture

All API and admin traffic is encrypted with TLS 1.3 in transit. Stored documents and biometric templates are encrypted with AES-256 at rest. Data-handling architecture is aligned with GDPR Articles 5, 17, and 25: data minimization, right-to-erasure, and privacy by design. This is architectural alignment, not an external certification. More detail is available on the security page.

Changes to this notice

Stile may update this notice as the product, legal requirements, or data-processing practices change. When the change is material, Stile will update the date above and use reasonable channels to make the updated notice available.

Privacy FAQ

Common privacy questions, answered directly

A short version of the data-handling model for users, merchants, and diligence reviewers.

Stile does not sell biometric or verification data. Optional public website data may be disclosed to analytics or company-identification providers in ways some state privacy laws treat as a sale or sharing. You can opt out through Privacy Choices or Global Privacy Control. These public website tools do not receive verification documents or biometric data.

Not in the default configuration. The merchant receives a signed webhook with the eligibility decision, session ID, and configured result fields. Raw document fields, biometric templates, date of birth, and source images stay inside Stile's verification pipeline unless a merchant-specific flow explicitly requires additional fields.

Retention is configurable per account. The default is delete-on-completion after the verification session resolves and the signed webhook is delivered. Optional retention windows for chargeback or fraud-investigation lookback are configured by contract and measured in days.

Use the contact page and include enough context to locate the account or verification session. Because many verification sessions are initiated by a merchant, Stile may need to coordinate with that merchant before completing the request.

No. This page is a public factual notice. Customer-specific data-processing terms, retention settings, subprocessors, and any Data Processing Addendum are handled in the applicable merchant agreement.