This Biometric Data Policy explains our collection and use of device fingerprint data, which is classified as biometric data under GDPR Article 9. We only collect device fingerprints for security purposes.
1. Overview
Device fingerprinting is a security technology that creates a unique identifier for your device based on characteristics such as browser settings, screen resolution, and installed fonts. This identifier helps us prevent fraud, detect ban evasion, and protect user accounts.
Under GDPR, device fingerprinting is classified as a "special category" of biometric data (Article 9). We only collect and process this data for legitimate security interests.
2. What We Collect
We collect the following device characteristics to generate a fingerprint:
- Browser information: User agent string, browser version, language
- Screen properties: Resolution, color depth, pixel ratio
- Hardware information: CPU cores, device memory, GPU information
- Timezone and locale settings
- Font detection: List of installed fonts
- Canvas and WebGL fingerprinting: Graphics rendering characteristics
- Audio fingerprinting: Audio context characteristics
3. How We Use Device Fingerprints
We use device fingerprints exclusively for security purposes:
- Ban evasion prevention: Detecting users attempting to circumvent account restrictions
- Fraud detection: Identifying suspicious login patterns
- Account security: Recognizing trusted devices for login
- Rate limiting: Preventing abuse of API endpoints and features
- Session management: Enhancing session security
We do not use device fingerprints for:
- Advertising or marketing
- Tracking user behavior across websites
- Profiling or personalization
- Selling data to third parties
4. Legal Basis
Under GDPR Article 9, we rely on the following legal basis for processing biometric data:
- Legitimate Interest (Article 9(2)(g)): We have a legitimate interest in protecting our platform from fraud, abuse, and security threats. This interest outweighs the minimal privacy impact of device fingerprinting.
- Explicit Consent: Users are informed of device fingerprinting through our cookie consent banner and can decline by not using our Service.
For users under GDPR jurisdiction, your rights to object to processing under legitimate interest are explained in Section 7.
5. Storage & Retention
5.1 How We Store Fingerprints
Device fingerprints are stored as SHA-256 hashes in our database. The raw fingerprint data is never stored, only the hash value. This makes it impossible to reverse-engineer the original device characteristics.
5.2 Retention Period
Device fingerprints are retained according to the following schedule:
- Active users: Retained for the duration of account activity
- Users with strikes/punishments: Retained for "duration of punishment + 90 days"
- Guest users: IP hashes retained for 30 days for rate limiting
- Terminated accounts: Retained indefinitely to prevent re-registration
See our Data Retention Schedule for detailed retention information.
6. Security Measures
We implement robust security measures to protect fingerprint data:
- Hashing: All fingerprints are hashed using SHA-256 before storage
- Encryption: Database encryption at rest (AES-256)
- Access controls: Strict access limits for fingerprint data
- No reverse engineering: Hashing prevents reconstruction of original data
- Regular security audits: Periodic reviews of fingerprint security
7. Your Rights
Under GDPR, you have the following rights regarding your device fingerprint data:
7.1 Right to Information
You have the right to know if we process your device fingerprint data. This policy fulfills that obligation.
7.2 Right to Access
You can request a copy of the device fingerprint hash associated with your account by contacting us.
7.3 Right to Object
You may object to the processing of your device fingerprint data on grounds relating to your particular situation. If you object, we may not be able to provide full security protections.
7.4 Right to Deletion
When you delete your account, your device fingerprint data is deleted according to our retention schedule. Fingerprints associated with terminated accounts may be retained for security purposes.
7.5 Right to Restriction
You may request that we limit the processing of your fingerprint data to essential security functions only.
To exercise any of these rights, contact us at support@thespencerwebsite.com.
8. Contact
For questions about this Biometric Data Policy or to exercise your rights, contact us:
Email: support@thespencerwebsite.com