Event Photo Face Search: Privacy and Consent Explained
Wondering how face-search photo platforms handle your biometric data? Here's what consent, data retention, and your rights actually look like.
Face-search photo platforms use facial recognition to match attendees to their event photos, and yes, that involves processing biometric data — which means consent, data handling, and deletion policies genuinely matter. Here's a plain-language breakdown of how responsible platforms handle this, and what Snapped specifically does.
What Counts as Biometric Data in This Context?
When you scan your face on a photo-matching platform, the system converts your facial geometry into a mathematical representation — sometimes called a faceprint or facial vector. This is biometric data under laws like the Illinois Biometric Information Privacy Act (BIPA), the EU's GDPR, and several other state and national frameworks. It's a different category from a regular photo: it's derived data that can be used to identify you.
Not every platform treats it the same way. The questions worth asking:
- Is consent obtained before the scan?
- What is the data used for beyond matching?
- How long is it retained?
- Can you request deletion?
How Snapped Handles Your Face Scan
Consent first. You are asked to consent explicitly before any facial scan is initiated. The consent screen explains what the scan is used for in plain language — not buried in a terms-of-service wall.
Limited purpose. Your facial data is used only to match you to photos in the event gallery you're searching. It is not used for advertising, sold to third parties, or used to train AI models.
Retention and deletion. Snapped does not store your faceprint indefinitely. After matching is complete, the biometric representation is deleted. If you want to confirm deletion or request it manually, you can contact Snapped directly.
No account required to search. You don't need to create a profile for your face data to persist somewhere. The scan is session-based.
What Laws Apply?
Biometric privacy law varies significantly by location:
- Illinois (BIPA) — one of the strictest in the US; requires written consent, limits data sharing, mandates deletion schedules
- Texas and Washington — similar consent and deletion requirements
- GDPR (EU/UK) — biometric data is a "special category" requiring explicit consent and strict purpose limitation
- California (CPRA) — biometric data classified as sensitive personal information with opt-out rights
If you're in one of these jurisdictions, you have specific legal rights around how your biometric data is collected and used. A platform operating responsibly will comply regardless of whether you ask.
Red Flags to Watch For
Not all event photo platforms are built the same. Be cautious if a platform:
- Doesn't mention biometric data or consent before asking you to scan
- Has vague language like "we may use your data to improve our services" without specifics
- Doesn't offer a clear deletion or opt-out path
- Requires account creation that links your face to a persistent profile
What About the Photographers?
Photographers who upload images to Snapped agree to terms that govern how attendee images are used. The photos themselves (the JPEGs) are not the same as the biometric data derived from scanning your face — but photographers are still responsible for how they collect and store images of identifiable people, particularly in jurisdictions with strong privacy laws.
The Short Version
Face-search photo delivery can be done in a privacy-respecting way. The key markers are: explicit consent before scanning, a narrow stated purpose, no third-party data sharing, and a clear deletion process. Snapped is built around those principles. If you have specific questions about your data, you can reach out directly — that's a reasonable thing to ask any platform handling biometric information.