Legal
Privacy Policy
BoundIdentity stores attestations, hashes, DIDs, and operational metadata. Passport and ID images stay with the IDV provider.
What we collect
Work email, organization name, tenant slug, billing identifiers (Stripe customer / subscription ids), API request logs (redacted), device/IP hashes for anti-abuse, and verifiable credential hashes.
What we do not store
Government ID images, full legal names in cleartext from ID documents, or raw biometric templates.
Processors
Infrastructure hosting, Stripe (payments), optional Resend (receipts), optional OpenAI (checkout advisor), and Shufti Pro (or equivalent IDV) when live KYC is enabled.