Validated by ValidateKey
Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains how SparxNovate LLC ("SparxNovate," "we," "us," or "our") collects, uses, shares, and protects information when you use ValidateKey. ValidateKey is a product of SparxNovate. This Policy applies to the ValidateKey website, application, organization workspace, and Enterprise API unless a separate written agreement says otherwise.
1. Information we collect
- Account and profile information: username or credential ID, name, date of birth, nationality, telephone number, email address, address, and, for an organization, registration, tax, address, and representative details you choose to provide.
- Passkey and device information: a passkey credential identifier, selected finger label, creation time, verification result, and related technical data. The platform authenticator performs the fingerprint comparison. We do not receive a raw fingerprint image through the passkey workflow.
- Live video check information: camera permission, challenge progress, completion result, timing, and technical signals needed to determine whether the live movement challenge was completed. The current live check is designed to process the camera stream in the browser and not upload or save the video itself.
- Backup PIN information: a one-way cryptographic hash of the PIN, not the PIN in readable form. We do not need your PIN to be returned to us in plain text.
- Use and technical information: verification attempts, timestamps, browser and device details, approximate service diagnostics, API request metadata, and organization membership or role information.
- Communications: information you provide when you contact support or receive account, security, or registration messages.
2. How we use information
- Provide, operate, maintain, and secure ValidateKey.
- Enroll and verify passkey credentials and display verification status.
- Run the live presence workflow and prevent attempts to use still images or recordings.
- Store profile information and account progress at your direction.
- Send registration confirmations, service notices, and security messages.
- Provide organization workspaces, invitations, audit trails, and Enterprise API responses.
- Monitor abuse, troubleshoot failures, investigate incidents, and enforce our Terms.
- Meet legal obligations and protect the rights, safety, and property of users and SparxNovate.
- Improve reliability and the user experience using information that is reasonably necessary.
3. Legal bases and permissions
Where privacy law requires a legal basis, we rely on performance of a contract, your instructions and consent, legitimate interests such as security and service improvement, and compliance with legal obligations. You can refuse browser permissions, but some features, including passkey enrollment, fingerprint verification, and live video checks, may not work without them. A browser or device may separately ask for permission to use a camera or platform authenticator.
4. Local browser and device storage
ValidateKey may store selected credential metadata, verification attempt history, the last reader test, and a persistent sign-in indicator in your browser's local storage. This local data is not the same as a fingerprint image. You can clear it through your browser controls, although doing so may require you to enroll or sign in again. Your operating system and browser may store and sync passkeys under their own policies and controls.
5. When we share information
We may share information in the following limited circumstances:
- With your organization: when you use an organization invitation or enterprise workflow, authorized administrators may receive the information and verification results needed for that workflow.
- With service providers: with hosting, database, email, security, analytics, and infrastructure providers that process information for us under appropriate instructions and confidentiality obligations.
- With your instructions: when you ask us to send a result to an authorized system through the Enterprise API or otherwise direct us to share it.
- For legal and safety reasons: when reasonably necessary to comply with law, respond to lawful process, investigate fraud or abuse, or protect people and the service.
- As part of a business change: in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law.
We do not sell personal information for money.
6. Enterprise and organization responsibilities
An organization may act as the controller or business that decides why information is collected, while SparxNovate may act as its service provider or processor. The organization's privacy notice, instructions, retention rules, and agreement with SparxNovate may apply to information processed for that organization. Direct requests about an organization's use of your information should also be sent to that organization.
7. Retention
We retain information for as long as reasonably necessary to provide the requested service, maintain security and audit records, meet legal obligations, resolve disputes, and enforce agreements. Retention can differ by account type, organization instructions, and the type of record. When information is no longer needed, we delete it, de-identify it, or securely isolate it where deletion is not immediately possible. Browser-local data remains until you or your browser removes it.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, alteration, disclosure, and destruction. No website, device, browser, passkey, or transmission is completely secure. You are also responsible for using a trusted device, keeping your operating system current, protecting your PIN, and signing out of shared devices.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing; receive a copy of certain information; withdraw consent; and appeal a decision about a privacy request. You can update some profile information in ValidateKey settings and clear browser-local data through your browser. To make a privacy request, contact SparxNovate through your ValidateKey support channel. We may need to verify your request before acting and may retain limited information where the law allows or requires it.
10. Children
ValidateKey is not directed to children who are not legally able to enter the agreement required to use the service. We do not knowingly collect personal information from such children. If you believe a child provided information, contact us through the available support channel so we can review and take appropriate action.
11. International processing
SparxNovate and its service providers may process information in countries other than the country where you live. Where required, we use appropriate safeguards for cross-border transfers. Your local law may give you additional rights concerning international processing.
12. Changes to this Policy
We may update this Policy as ValidateKey, our practices, or privacy law changes. We will post the updated Policy and revise the date above. If a change is material, we will use a reasonable additional notice method when required. Your continued use of ValidateKey after the updated Policy takes effect means the updated Policy applies to future use.
13. Contact
ValidateKey is a product of SparxNovate LLC. For privacy questions or rights requests, use the support or contact channel provided with your ValidateKey account or organization workspace.
