Privacy policy
This policy covers the CVShot and IDShot apps and the service behind them. It describes what the service actually does today.
Who we are
OID4Pay B.V., the Netherlands. KvK 42074824. Contact: [email protected].
Who can use the apps
You must be 18 or older to use CVShot or IDShot.
What we process, and why
- Your account. When you sign in with Google or Apple we receive your email address and the account identifier Google or Apple gives us for you (your Google or Apple account id). With Google, your name is taken from your Google account profile automatically when it is available. With Apple, we receive your name only if you choose to share it on your first sign-in. We use these to identify your account. Legal basis: performance of our contract with you (GDPR art. 6(1)(b)).
- Your selfie. The photo you take is sent to our server and passed to Google's Gemini API to create your headshot or document photo. Our server keeps the selfie in memory only while it is processed and never stores it. Google processes it as our processor under its paid-service terms, which say Google does not use it to improve its products. In IDShot only, on-device camera checks (face position, eyes open) run on your phone and send nothing anywhere; CVShot has no such checks.
- Your generated photos. Stored on our server so you can download them, and deleted automatically after 30 days. You can delete any of them sooner in the app.
- Credits. A record of credits granted, bought, used and refunded, kept for as long as you have an account.
- Purchases. Credit packs are bought through Google Play. Google processes the payment; we never see your card or bank details. From Google we receive and store the order id, the purchase token, the product, the time of purchase, the number of credits granted, and any refund or chargeback. We keep these purchase records for 7 years, as Dutch tax law requires for bookkeeping, also after you delete your account (they are then no longer linked to it). Legal basis: legal obligation (GDPR art. 6(1)(c)).
- Reports. If you report a generated photo, we store your reason, your optional note and the time. The report and the reported photo are kept for review until the report is resolved, and for at most 30 days.
- Server logs. For each request our server logs the time, the route, the response code, the request id and, if you are signed in, your account id. It does not log photos, notes or your IP address; the IP address is only held in the server's memory to limit abusive request rates and is never written to disk. Logs are kept for a limited period to keep the service secure and working.
We do not use advertising or tracking tools, and we do not sell your data.
Where it is stored, and who else processes it
- Our own server in the Netherlands stores everything listed above.
- Google (Gemini API) processes selfies as described above.
- Google Play handles purchases and payment, under Google's own privacy policy.
- Cloudflare carries all traffic between the app and our server (the secure connection and tunnel to our server). It processes your IP address and request data for that purpose, as our processor.
Your rights
- Access: download everything we store about you from the app's settings. The download is a JSON file with your account, sign-in providers, credit history, purchases, generated photo records and reports. Purchases are listed by order id; purchase tokens are left out.
- Deletion: delete your account in the app's settings, or see how to delete your account. This immediately removes your account, photos, reports and credit history from the live system. Purchase records are kept for bookkeeping as described above. Encrypted backups are kept for up to 5 weeks and are then overwritten, so deleted data disappears from them within that time.
- You can also ask us for correction or restriction, and you can complain to the Autoriteit Persoonsgegevens.