This Privacy Statement applies to the GAMBIT ID CO. (“GAMBIT ID”) mobile, web based and cloud hosted commercial product applications (the “Services”) and governs the collection and use of data in connection with the Services. GAMBIT ID CO. is committed to protecting the personally identifiable information (“PII”) and other non-PII data (“Data”) of its customers and end-users (collectively “Users”) that is collected and used in connection with the Services. It does not apply to any information an entity collects for its own use. Use of the Services constitutes agreement and consent to the practices described in this statement.
The Services provide a way to securely authenticate identification documents and verify user identity and/or interact with third-party websites (“Websites”). However, this policy does not cover any Websites of third parties. GAMBIT ID CO. encourages Users to review the privacy statements of other Websites that the User interacts with using the Services to understand how those Websites collect, use, and share personal information and other data. GAMBIT ID CO. is not responsible for the privacy statements or other content on Websites outside of the Services or the practices of any third parties which a User wishes to interact with in using the Services.
GAMBIT ID CO. Services may collect PII (Personally Identifiable Information) and Data, which may include the following:
GAMBIT ID CO. may use the information collected through the Services in the following way:
Stateful Services deliver value through the long-term storage of User PII. An example of a stateful Service is the storage of biometric information to perform 1:1 and 1:N matching for User identification and verification. Stateless Services provide Users value without the need for long-term storage of PII. An example of a stateless product and/or service is the process of determining if a presented document is authentic (e.g., determining the authenticity of a US Driver’s License).
PII for Stateful Services will be retained until one of the following events occurs:
PII for Stateless Services will be used as follows:
Data that does not contain PII or has been anonymized will be retained indefinitely to test and improve the Services and related products, including:
GAMBIT ID CO. secures PII by encrypting PII data at rest and in transit. All PII is protected on computer servers in a controlled, secure environment that is protected from unauthorized access. When PII is transmitted, it is protected through the use of encryption, such as Transport Layer Security (TLS) or Secure Sockets Layer (SSL) protocols to protect against unintended recipients obtaining access to PII.
Multi-Factor Authentication is deployed at the application level for additional security. After users log out or if they have been logged out due to the expiration of a proscribed shift, they are required to submit username and password. Upon successful authentication, the user receives a 6-digit code either via a text to the phone or via an email message.
Questions or comments regarding this Privacy Statement should be directed to GAMBIT ID CO. at scanmobile@gambitid.com. GAMBIT ID CO. will use commercially reasonable efforts to promptly understand and address the issue.
Users may opt-out of the collection of PII or Data by GAMBIT ID CO. by canceling the Services and uninstalling the applications from all User devices.
GAMBIT ID CO. will occasionally update this Privacy Statement. The latest version of the Privacy Statement can be found at https://www.gambitidscan.com/privacy.html. Downloading or use of the Services after any changes to this Privacy Statement constitutes consent to the revised Privacy Statement.