Biometric Data Policy
Effective date: October 8, 2026 · Operator: PRH Services LLC d/b/a Pinks Play World, 117 Smithtown Road, Ashland, VA 23005 · hello@pinksplay.world
What we collect
Before your first prize redemption we verify your identity with Didit, our identity verification provider. Didit checks your government photo ID and a short live selfie, and measures your face geometry to compare the two and confirm you are present. These measurements, and anything derived from them, are "biometric identifiers" and "biometric information" (together, biometric data) under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, Colorado law and similar laws.
Notice and consent first
We show you a written notice and ask for your written consent before the check starts. We record when you agreed and which version of the notice you saw. If you don't consent, no biometric data is collected; you can keep using your account, but we can't pay prizes without a completed check.
Why we use it
Only to verify your identity and age (21+) and to prevent fraud and duplicate accounts. We do not use biometric data for marketing, profiling or any other purpose.
Who handles it
Didit processes biometric data on our behalf under a written contract. We do not sell, lease, trade or otherwise profit from biometric data, and we do not disclose it to anyone else unless you consent, it completes a transaction you asked for, or the law, a valid warrant or subpoena requires it.
How long we keep it
We permanently destroy biometric data at the earlier of: (a) when the purpose it was collected for is fulfilled, or (b) 1 year after your last interaction with us. In Illinois this is never longer than the 3-year limit in 740 ILCS 14/15(a); in Texas it is within one year of the purpose expiring.
- Approved checks: our copy of the verification record is deleted 30 days after approval.
- Denied checks: deleted 90 days after the decision, so you can appeal.
- Checks you start and don't finish: deleted after 30 days.
- Anything else, such as a check still waiting on review or a closed account: deleted no later than 1 year after the last activity on it.
- Each time we delete our copy, we also instruct Didit to delete its copy of that verification session.
How we protect it
We protect biometric data with at least the care we use for our other confidential information: encryption in transit, access limited to authorized staff, and an audit log of every verification decision and deletion.
If there's a security incident
If we learn that biometric data may have been accessed without permission, we contain the incident, find out what happened and whose data was involved, and tell Didit to secure its copy. We notify affected people, and regulators where the law requires, as fast as we can and no later than state law allows (in Colorado, within 30 days). Didit must tell us promptly about any incident on its side.
Your rights
You can ask what biometric data we hold about you, or ask us to delete it sooner, by emailing hello@pinksplay.world. See also our Privacy Policy.