Biometric Information Privacy Policy
Policy version: v1.0
Last updated: June 1, 2026
Overview
SummerBoss offers camps an optional facial-recognition feature that helps a parent or guardian find photos of their own child within a camp session's private photo gallery. This policy explains what biometric data we collect, how we use it, who processes it, how long we keep it, and how it is destroyed. Facial recognition is strictly opt-in and is never enabled for a child unless that child's parent or guardian has given explicit, written consent.
What we collect
With consent, we generate a facial recognition template (a mathematical representation of facial geometry — a "biometric identifier") from a reference photo the parent uploads or confirms. We also retain that reference photo. We do not collect fingerprints, voiceprints, retina/iris scans, or any other biometric identifier.
Consent disclosure (verbatim)
The text above is the exact wording shown to a parent immediately above the opt-in control inside SummerBoss. A SHA-256 hash of this string, along with a timestamp, IP address, and user-agent, is stored alongside each consent event so we can evidence the exact wording each parent agreed to (policy version v1.0).
How we use it
The face template is used for one purpose only: to match the consented child within the photos of the camp session(s) they are enrolled in, so the parent can be notified and can find those photos. We never sell, lease, trade, or otherwise profit from biometric identifiers, and we never use them for advertising, marketing, or any other purpose.
Processor (Amazon Web Services)
Facial recognition is performed using Amazon Rekognition (Amazon Web Services, Inc.) on servers in the United States. Face templates are stored in an access-controlled collection that is isolated per organization. AWS acts as our sub-processor and does not use the data for its own purposes.
Retention and destruction schedule
- We destroy a child's face template and reference photo when the matching purpose ends — at the end of the camp session/season plus 30 days.
- We destroy them immediately when a parent revokes consent.
- In all cases, we destroy biometric identifiers within three (3) years of the parent's last interaction, whichever occurs first.
- Consent must be renewed each season; we do not silently carry biometric data across seasons.
- We retain the consent record itself (not the biometric data) longer, solely to evidence that consent was given.
Your controls
A parent or guardian can review, decline, or revoke facial-recognition consent for each child at any time in their SummerBoss account settings. Revoking consent deletes the stored face template and reference photo and de-indexes the child from the recognition collection. Children whose parents decline still appear in galleries subject to the camp's photo/media-release policy and can be tagged manually; they are never run through facial recognition.
State notices
Residents of Illinois (BIPA, 740 ILCS 14), Texas (CUBI, Bus. & Com. Code §503.001), Washington (RCW 19.375), and other states with biometric-privacy laws have specific rights. Where facial recognition is restricted or prohibited for a resident's state, the opt-in is disabled and no biometric template is created or searched; galleries continue to work with manual tagging. We provide notice and obtain written consent before collecting any biometric identifier, do not sell or profit from it, and destroy it under the schedule above.
Privacy & terms
Contact
Questions about biometric data or to exercise your rights, email legal@summerboss.com.