Biometric Data Policy

How we collect, use, and protect device fingerprint data.

Updated May 5, 2026 Version 1.0

This Biometric Data Policy explains our collection and use of device fingerprint data, which is classified as biometric data under GDPR Article 9. We only collect device fingerprints for security purposes.

Related policies: Privacy Policy ยท Data Retention Schedule

1. Overview

Device fingerprinting is a security technology that creates a unique identifier for your device based on characteristics such as browser settings, screen resolution, and installed fonts. This identifier helps us prevent fraud, detect ban evasion, and protect user accounts.

Under GDPR, device fingerprinting is classified as a "special category" of biometric data (Article 9). We only collect and process this data for legitimate security interests.

2. What We Collect

We collect the following device characteristics to generate a fingerprint:

  • Browser information: User agent string, browser version, language
  • Screen properties: Resolution, color depth, pixel ratio
  • Hardware information: CPU cores, device memory, GPU information
  • Timezone and locale settings
  • Font detection: List of installed fonts
  • Canvas and WebGL fingerprinting: Graphics rendering characteristics
  • Audio fingerprinting: Audio context characteristics
We do not collect: Actual fingerprints, facial recognition data, voice patterns, iris scans, or any other traditional biometric identifiers.

3. How We Use Device Fingerprints

We use device fingerprints exclusively for security purposes:

  • Ban evasion prevention: Detecting users attempting to circumvent account restrictions
  • Fraud detection: Identifying suspicious login patterns
  • Account security: Recognizing trusted devices for login
  • Rate limiting: Preventing abuse of API endpoints and features
  • Session management: Enhancing session security

We do not use device fingerprints for:

  • Advertising or marketing
  • Tracking user behavior across websites
  • Profiling or personalization
  • Selling data to third parties

5. Storage & Retention

5.1 How We Store Fingerprints

Device fingerprints are stored as SHA-256 hashes in our database. The raw fingerprint data is never stored, only the hash value. This makes it impossible to reverse-engineer the original device characteristics.

5.2 Retention Period

Device fingerprints are retained according to the following schedule:

  • Active users: Retained for the duration of account activity
  • Users with strikes/punishments: Retained for "duration of punishment + 90 days"
  • Guest users: IP hashes retained for 30 days for rate limiting
  • Terminated accounts: Retained indefinitely to prevent re-registration

See our Data Retention Schedule for detailed retention information.

6. Security Measures

We implement robust security measures to protect fingerprint data:

  • Hashing: All fingerprints are hashed using SHA-256 before storage
  • Encryption: Database encryption at rest (AES-256)
  • Access controls: Strict access limits for fingerprint data
  • No reverse engineering: Hashing prevents reconstruction of original data
  • Regular security audits: Periodic reviews of fingerprint security

7. Your Rights

Under GDPR, you have the following rights regarding your device fingerprint data:

7.1 Right to Information

You have the right to know if we process your device fingerprint data. This policy fulfills that obligation.

7.2 Right to Access

You can request a copy of the device fingerprint hash associated with your account by contacting us.

7.3 Right to Object

You may object to the processing of your device fingerprint data on grounds relating to your particular situation. If you object, we may not be able to provide full security protections.

7.4 Right to Deletion

When you delete your account, your device fingerprint data is deleted according to our retention schedule. Fingerprints associated with terminated accounts may be retained for security purposes.

7.5 Right to Restriction

You may request that we limit the processing of your fingerprint data to essential security functions only.

To exercise any of these rights, contact us at support@thespencerwebsite.com.

8. Contact

For questions about this Biometric Data Policy or to exercise your rights, contact us:

Email: support@thespencerwebsite.com