Saconde & Saconde, LLC
Effective Date: July 11, 2026
Company Name: Saconde & Saconde, LLC
Principal Place of Business: New York, New York, United States
Website: www.saconde.com
Mobile Applications: Saconde mobile applications, including applications made available for iOS, Android, or other supported platforms
Retail/Showroom Location: 521 W 26th St, Floor 5, New York, NY 10001
Contact: hello@saconde.com
1. PURPOSE
Saconde & Saconde, LLC, doing business as Saconde (“Saconde,” “Company,” “we,” “us,” or “our”), adopts this Biometric Data Retention and Destruction Policy (“Policy”) to establish:
- the purposes for which Saconde may collect or process Biometric Data;
- the periods for which such information may be retained;
- the events that trigger deletion;
- procedures for permanent destruction;
- security and access-control requirements;
- service-provider requirements;
- incident-response requirements;
- and procedures for complying with biometric privacy and comprehensive consumer privacy laws.
This Policy is intended to satisfy or exceed the requirements of applicable law, including laws that require a publicly available written biometric retention and destruction policy.
2. SCOPE
This Policy applies to Biometric Data collected, captured, received, generated, converted, stored, possessed, controlled, used, disclosed, or otherwise processed by or on behalf of Saconde in connection with:
- Saconde’s mobile applications;
- Saconde’s website;
- Saconde customer, buyer, seller, and consignor accounts;
- biometric login;
- identity verification;
- account recovery;
- fraud prevention;
- payment or payout security;
- high-value transactions;
- facility or system access;
- employee or contractor security;
- and other services that link to this Policy.
This Policy applies to:
- customers;
- buyers;
- sellers;
- consignors;
- website visitors;
- app users;
- account holders;
- employees;
- applicants;
- contractors;
- service providers;
- and other individuals whose Biometric Data Saconde processes.
3. DEFINITIONS
3.1 Biometric Identifier
“Biometric Identifier” means a biological, physiological, or behavioral characteristic, or data generated through automated measurement of such a characteristic, used or intended to identify or authenticate a particular individual.
Examples may include:
- fingerprints;
- voiceprints;
- iris or retina scans;
- hand or palm geometry;
- face geometry;
- facial-recognition templates;
- liveness templates;
- and other unique biological or behavioral patterns used for identification.
3.2 Biometric Information
“Biometric Information” means information based on, derived from, or generated from a Biometric Identifier and used or intended to identify or authenticate an individual.
3.3 Biometric Data
“Biometric Data” means Biometric Identifiers and Biometric Information, subject to applicable statutory definitions and exclusions.
3.4 Authentication Metadata
“Authentication Metadata” means non-biometric records associated with an authentication event, such as:
- success or failure;
- timestamp;
- device type;
- operating-system version;
- account identifier;
- session identifier;
- encrypted token;
- public key;
- security log;
- risk signal;
- or diagnostic code.
Authentication Metadata is not treated as Biometric Data unless it contains, is derived from, or is reasonably capable of being used as covered biometric information under applicable law.
3.5 Permanent Destruction
“Permanent Destruction” means deletion, erasure, cryptographic destruction, secure overwriting, physical destruction, or another process reasonably designed to render information permanently unreadable, unrecoverable, and incapable of reconstruction in the ordinary course of business.
4. POLICY PRINCIPLES
Saconde will follow these principles:
- Purpose limitation: Collect and use Biometric Data only for specific, disclosed, legitimate, and lawful purposes.
- Data minimization: Collect only the minimum information reasonably necessary and proportionate to the purpose.
- Consent: Obtain advance notice and affirmative consent when required.
- Alternative access: Provide a reasonable non-biometric alternative when required or reasonably practicable.
- No sale: Never sell, lease, trade, or otherwise profit from Biometric Data.
- Limited disclosure: Disclose Biometric Data only as authorized by law and this Policy.
- Security: Protect Biometric Data using safeguards appropriate to its sensitivity.
- Limited retention: Retain Biometric Data only for as long as reasonably necessary and legally permitted.
- Permanent destruction: Permanently destroy Biometric Data when the applicable retention period expires.
- Accountability: Document collection, access, disclosure, retention, and destruction where reasonably practicable.
- Privacy by design: Evaluate privacy and security risks before introducing a new biometric technology.
- No repurposing: Do not materially change the purpose without additional notice and consent where required.
5. DEVICE-NATIVE BIOMETRIC LOGIN
Saconde’s preferred biometric-login architecture is device-native authentication.
For device-native authentication:
- the device or operating-system provider performs the biometric comparison;
- the underlying fingerprint, face map, iris pattern, or biometric template should remain on the user’s device or within the provider’s secure environment;
- Saconde should receive only an authentication result, token, public-key assertion, or similar confirmation;
- Saconde should not receive or retain raw biometric measurements;
- Saconde should not attempt to extract biometric templates from a user’s device;
- and Saconde should not use authentication results to infer personal characteristics.
Where Saconde does not possess the underlying Biometric Data, this Policy does not require Saconde to destroy information it never received or controlled. Users must manage biometric enrollment stored by their device through the device’s settings.
Authentication Metadata will be retained under Saconde’s general security-log schedule rather than as raw Biometric Data, unless applicable law requires different treatment.
6. APPROVED PURPOSES
Saconde may process Biometric Data only for an approved purpose, including:
- optional account login;
- user authentication;
- identity verification;
- account recovery;
- fraud prevention;
- prevention of account takeover;
- prevention of theft or unauthorized transactions;
- verification of changes to payment, payout, banking, address, or shipping information;
- authentication for high-value transactions;
- access to restricted systems, facilities, or high-value inventory;
- compliance with legal or regulatory obligations;
- cybersecurity;
- security investigations;
- enforcement of agreements;
- or another specific purpose approved through Saconde’s privacy-review process.
The following uses are prohibited unless expressly authorized by law and approved through enhanced legal review:
- targeted advertising;
- unrelated consumer profiling;
- emotion recognition;
- demographic inference;
- covert facial recognition;
- general surveillance;
- individualized pricing based on biometric characteristics;
- determining eligibility for credit, insurance, employment, housing, or public accommodations;
- and processing intended to infer protected or highly sensitive characteristics.
7. APPROVAL OF NEW BIOMETRIC TECHNOLOGY
Before implementing or materially changing biometric technology, Saconde must complete a documented review addressing:
- the proposed technology;
- the precise purpose;
- the categories of individuals affected;
- the categories of Biometric Data involved;
- whether the data remains on the device;
- whether Saconde or a provider receives a biometric template;
- whether a non-biometric alternative exists;
- the legal basis for processing;
- notice and consent requirements;
- effects on minors;
- retention periods;
- service-provider involvement;
- data-storage location;
- security safeguards;
- cross-border transfers;
- possible bias, discrimination, or accessibility concerns;
- required privacy or data-protection assessments;
- and deletion capabilities.
No business unit, employee, contractor, or service provider may independently deploy biometric technology on Saconde’s behalf without written authorization.
8. NOTICE AND CONSENT REQUIREMENTS
Before directly collecting or obtaining Biometric Data, Saconde must provide a clear notice that identifies:
- the fact that Biometric Data will be collected or stored;
- the categories of data;
- the specific purposes;
- how the information will be used;
- whether it will be disclosed;
- the retention period;
- the destruction process;
- the individual’s rights;
- whether processing is optional;
- available alternatives;
- and how to withdraw consent.
Where required, Saconde must obtain a written release or affirmative consent before collection.
Consent must be:
- freely given;
- specific;
- informed;
- unambiguous;
- presented separately from unrelated terms where required;
- recorded in a durable form;
- and capable of withdrawal.
Silence, inactivity, or use of a service without an affirmative action will not constitute consent where affirmative consent is required.
Saconde will not use dark patterns to obtain consent.
9. RETENTION SCHEDULE
9.1 General Rule
Saconde will retain Biometric Data only until the earliest of:
- satisfaction of the initial purpose for collection;
- expiration of the applicable period listed below;
- withdrawal of consent, where no other lawful basis permits continued retention;
- completion of a verified deletion request;
- termination of the relationship that justified collection;
- expiration of a legally required retention period;
- or another date required by applicable law.
9.2 Device-Native Biometric Login
Data retained by Saconde: Saconde generally retains no raw biometric identifier or template.
Authentication Metadata: Ordinarily retained for up to 24 months after the authentication event for security, fraud prevention, auditing, and troubleshooting, unless:
- a shorter period is required;
- the information is aggregated or deidentified;
- or a longer period is required for a documented security investigation, litigation hold, or legal obligation.
Biometric-login preference: Retained until:
- the user disables biometric login;
- the account is closed;
- the app is reset or reinstalled;
- the device credential is revoked;
- or the preference is otherwise deleted.
9.3 Directly Collected Biometric Login Templates
Saconde should not ordinarily collect or retain a central biometric-login template.
If Saconde later implements such a system, the template must be destroyed by the earliest of:
- completion of the authentication purpose;
- disabling of biometric login;
- closure of the account;
- three years after the individual’s last interaction with Saconde;
- one year after the purpose expires for individuals covered by a shorter statutory period;
- withdrawal of consent;
- or another deadline required by law.
9.4 Identity-Verification Selfies, Videos, and Derived Face Data
Unless a supplemental notice specifies a shorter period:
- raw selfie images or verification videos should be deleted within 30 days after successful verification;
- failed or incomplete verification records should be deleted within 30 days after the verification session ends;
- facial templates, face-geometry data, liveness templates, and match vectors should be deleted immediately after completion of verification or within 30 days at the latest;
- verification results and non-biometric audit records may be retained for up to five years where reasonably necessary for fraud prevention, dispute resolution, legal compliance, or proof that verification occurred.
A raw image may be retained longer only when:
- required by law;
- reasonably necessary to investigate suspected fraud, theft, counterfeiting, sanctions evasion, identity theft, or account takeover;
- subject to a litigation hold;
- necessary to resolve a dispute;
- or specifically authorized by the individual and permitted by law.
When an exception ends, the data must be promptly destroyed.
9.5 Account Recovery
Biometric Data collected solely for account recovery must be destroyed:
- immediately after recovery is completed;
- within 30 days after an incomplete or abandoned recovery attempt;
- or sooner if required by law.
A non-biometric record confirming that account recovery occurred may be retained under the applicable security-log schedule.
9.6 Fraud and Security Investigations
Biometric Data associated with a documented fraud or security investigation may be retained until:
- the investigation is closed;
- related legal claims are resolved;
- applicable limitation periods expire;
- enforcement or regulatory proceedings conclude;
- and any legal hold is released.
Access must be restricted, and the reason for extended retention must be documented.
9.7 Employees and Contractors
Biometric Data collected from an employee or contractor must be destroyed by the earliest of:
- satisfaction of the original purpose;
- discontinuation of the biometric system;
- withdrawal of consent where legally controlling;
- three years after the individual’s last interaction with Saconde;
- three years after separation from Saconde;
- one year after the purpose expires where a shorter statutory period applies;
- or another date required by law.
Saconde should avoid retaining employee biometric templates centrally when device-native or card-based alternatives are reasonably available.
9.8 Applicants
Applicant Biometric Data must be destroyed when:
- the verification or screening purpose is complete;
- the applicant is no longer under consideration;
- the applicable challenge or dispute period expires;
- or within 90 days after the applicable process concludes, unless law requires or permits longer retention.
9.9 Physical Retail Locations
Biometric Data collected at a physical retail location must be retained only as long as necessary for the disclosed purpose.
Saconde may not implement customer facial-recognition or biometric-identification technology in a New York City retail location without first completing a legal review and implementing all legally required signage, notices, restrictions, and consent mechanisms.
9.10 Backups
Where Biometric Data exists in backups:
- active copies must be deleted promptly;
- backup copies must be placed beyond ordinary business use;
- backups must not be restored except for disaster recovery, security, or legal necessity;
- restored data must be subject to the original deletion request or schedule;
- and backup copies must be overwritten through the ordinary backup lifecycle, ordinarily within 90 days.
If technical limitations prevent immediate deletion from an immutable backup, Saconde must isolate the information from active processing and delete it when technically feasible.
9.11 Legal Holds
A legal hold temporarily suspends destruction only for information relevant to:
- pending or reasonably anticipated litigation;
- an investigation;
- a subpoena;
- a court order;
- a regulatory inquiry;
- an insurance claim;
- or another legal obligation.
The legal hold must:
- identify the scope of preserved data;
- restrict access;
- prohibit unrelated use;
- be reviewed periodically;
- and be released promptly when no longer necessary.
10. STRICTEST-APPLICABLE RETENTION RULE
When multiple laws apply, Saconde will use the shortest legally applicable retention period unless:
- a longer period is legally required;
- a specific exception applies;
- or deletion would interfere with a documented legal obligation or the establishment, exercise, or defense of legal claims.
As a nationwide operational baseline:
- Biometric Data will not be retained merely because storage is inexpensive or potentially useful;
- biometric templates will not be retained indefinitely;
- and every biometric-data category must have an assigned deletion trigger.
11. DESTRUCTION PROCEDURES
When destruction is required, Saconde will use methods reasonably designed to prevent reconstruction or future use.
Depending on the storage medium, methods may include:
- secure deletion;
- cryptographic erasure;
- destruction of encryption keys;
- secure overwriting;
- deletion from active databases;
- deletion from object storage;
- deletion from caches;
- deletion from development and testing environments;
- deletion from analytics systems;
- deletion from service-provider systems;
- deletion or isolation in backups;
- shredding physical records;
- and destruction of storage media.
Deletion must include:
- raw biometric samples;
- biometric templates;
- mathematical representations;
- derived biometric vectors;
- cached copies;
- duplicate records;
- exports;
- test records;
- and copies maintained by service providers, subject to lawful exceptions.
12. DESTRUCTION DOCUMENTATION
Saconde should maintain records sufficient to demonstrate compliance, including:
- the category of data destroyed;
- the applicable individual or record group;
- the destruction trigger;
- the date destruction was initiated;
- the date destruction was completed;
- the systems affected;
- the method used;
- service-provider confirmations;
- any exceptions;
- and the person or system responsible.
A destruction log must not itself contain unnecessary Biometric Data.
13. SERVICE-PROVIDER REQUIREMENTS
Before a service provider may process Biometric Data, Saconde must conduct reasonable due diligence concerning:
- the provider’s security;
- data-storage locations;
- subprocessors;
- retention practices;
- deletion capabilities;
- prior incidents;
- regulatory history;
- and ability to comply with applicable privacy laws.
Contracts should require the provider to:
- process Biometric Data only on documented instructions;
- use the information only for specified purposes;
- maintain confidentiality;
- implement appropriate security;
- limit access;
- prohibit sale and advertising use;
- prohibit independent profiling;
- avoid combining the data with unrelated information except as authorized;
- notify Saconde of a security incident without unreasonable delay;
- assist with privacy requests;
- maintain accurate records;
- delete or return Biometric Data at the end of services;
- require equivalent protections from subprocessors;
- permit reasonable compliance review or audit;
- comply with applicable retention deadlines;
- provide written deletion certification upon request;
- and notify Saconde before making a legally compelled disclosure unless prohibited by law.
14. DISCLOSURE RESTRICTIONS
Saconde will not disclose or disseminate Biometric Data except:
- with legally sufficient consent;
- to a contracted service provider;
- to complete a transaction requested or authorized by the individual;
- when required by law;
- under a valid warrant, subpoena, court order, or compulsory process;
- to protect against fraud, theft, or security threats where legally permitted;
- or for another expressly authorized purpose.
Before disclosing Biometric Data, Saconde should document:
- the recipient;
- the legal and business purpose;
- the categories disclosed;
- the date;
- the authority for disclosure;
- and applicable contractual protections.
15. PROHIBITION ON SALE AND MONETIZATION
Saconde will not:
- sell;
- lease;
- license for value;
- trade;
- monetize;
- exchange;
- or otherwise profit from a transaction involving Biometric Data.
Biometric Data will not be used as consideration in an advertising, analytics, data-broker, or commercial-data arrangement.
16. INFORMATION SECURITY
Saconde will maintain safeguards proportionate to the sensitivity of Biometric Data, including, where appropriate:
- encryption at rest and in transit;
- secure key management;
- hardware-backed key storage;
- tokenization or pseudonymization;
- network segmentation;
- least-privilege access;
- role-based access controls;
- multifactor authentication;
- secure development practices;
- code review;
- penetration testing;
- vulnerability management;
- logging;
- anomaly detection;
- endpoint security;
- data-loss prevention;
- employee training;
- vendor oversight;
- incident-response procedures;
- and secure disposal.
Biometric Data may not be stored:
- in unencrypted spreadsheets;
- in ordinary email;
- in personal cloud-storage accounts;
- on personal devices;
- in unsecured messaging applications;
- or in production logs not specifically designed for sensitive data.
17. ACCESS CONTROLS
Access to Biometric Data must be limited to personnel who require it for an authorized purpose.
Saconde should:
- maintain role-based access;
- review access periodically;
- promptly remove access after role changes or separation;
- log access where reasonably practicable;
- prohibit downloading unless necessary;
- prohibit use for testing without approval;
- and require confidentiality obligations.
Employees and contractors may not copy, export, share, or use Biometric Data for an unauthorized purpose.
18. DEVELOPMENT AND TESTING
Saconde will not use identifiable production Biometric Data in development, quality-assurance, demonstration, or testing environments unless:
- the use is necessary;
- no reasonable alternative exists;
- the use is approved;
- the data is minimized;
- access is restricted;
- security is equivalent to production;
- and the information is deleted promptly after testing.
Synthetic, anonymized, or non-identifiable test data should be used whenever possible.
19. DATA-PROTECTION ASSESSMENTS
Saconde will conduct and document a data-protection assessment before engaging in biometric processing that presents a heightened risk of harm or where an assessment is required by law.
The assessment should evaluate:
- necessity;
- proportionality;
- benefits;
- risks to individuals;
- possible discrimination or bias;
- accuracy;
- false match and false rejection risks;
- alternatives;
- security;
- retention;
- service-provider practices;
- minors;
- and measures taken to reduce risk.
20. INDIVIDUAL RIGHTS REQUESTS
Saconde will maintain procedures for receiving and responding to requests to:
- access;
- confirm processing;
- correct;
- delete;
- obtain a copy;
- withdraw consent;
- disable biometric login;
- restrict processing;
- opt out;
- or appeal a denied request.
Requests may be submitted to [INSERT PRIVACY EMAIL] or through [INSERT PRIVACY REQUEST URL].
Saconde will:
- reasonably verify identity;
- avoid collecting excessive verification data;
- respond within applicable legal deadlines;
- explain any denial;
- provide appeal instructions where required;
- and communicate deletion instructions to relevant processors or service providers.
21. MINORS
Saconde will not knowingly process a minor’s Biometric Data without legally required authorization.
Before collecting a minor’s Biometric Data, Saconde must determine whether:
- parental or guardian consent is required;
- the minor may consent under applicable law;
- the processing is necessary;
- a non-biometric alternative exists;
- enhanced notice is required;
- and a shorter retention period should apply.
Biometric Data of minors must not be used for advertising, unrelated profiling, or commercial surveillance.
22. INCIDENT-RESPONSE PROCEDURES
A suspected loss, unauthorized access, acquisition, disclosure, alteration, or destruction of Biometric Data must be reported immediately to Saconde’s designated privacy and security personnel.
Saconde’s response will include, as appropriate:
- containment;
- preservation of relevant evidence;
- identification of affected systems and individuals;
- assessment of the type of Biometric Data involved;
- determination of whether the information was encrypted or otherwise protected;
- investigation of the cause and scope;
- engagement of service providers or forensic specialists;
- legal analysis of notification duties;
- notification to individuals, regulators, law enforcement, insurers, or business partners where required;
- remediation;
- documentation;
- review of retention and access controls;
- and corrective action.
Because biometric characteristics generally cannot be reissued in the same manner as a password, incidents involving Biometric Data will be treated as high priority.
23. STATE-SPECIFIC REQUIREMENTS
23.1 Illinois
Saconde will:
- maintain this publicly available written retention schedule;
- provide written notice of collection or storage;
- disclose the specific purpose and length of term;
- obtain a written release;
- prohibit sale and profiting;
- limit disclosure;
- use a reasonable standard of care;
- protect biometric information at least as carefully as other confidential information;
- and permanently destroy covered information when the initial purpose has been satisfied or within three years of the individual’s last interaction with Saconde, whichever occurs first.
23.2 Texas
Saconde will:
- inform individuals and obtain consent before capture for a commercial purpose;
- restrict sale, lease, and disclosure;
- use reasonable care;
- protect biometric identifiers at least as carefully as other confidential information;
- and destroy covered identifiers within a reasonable time and no later than one year after the purpose expires, subject to legally permitted employment and security exceptions.
23.3 Washington
Saconde will:
- provide notice and obtain consent before enrollment in a database for a commercial purpose;
- obtain consent before a material change in purpose;
- maintain retention and deletion practices;
- prohibit materially inconsistent uses;
- restrict sale, lease, and disclosure;
- and guard against unauthorized access and acquisition using reasonable care.
23.4 Colorado
Saconde will:
- maintain a written policy governing retention, incident response, security-breach notification, and deletion;
- provide required disclosures;
- obtain valid consent;
- allow withdrawal;
- provide applicable access, correction, deletion, and appeal rights;
- avoid conditioning unrelated services on biometric consent;
- conduct required assessments;
- and delete biometric identifiers by the earliest applicable statutory deadline.
23.5 California
Where California law applies, Saconde will:
- treat biometric information used for unique identification as sensitive personal information;
- provide notice at or before collection;
- limit processing to reasonably necessary and proportionate purposes;
- provide applicable access, correction, deletion, limitation, opt-out, and nondiscrimination rights;
- honor recognized opt-out signals where applicable;
- and enter legally required contracts with service providers and contractors.
23.6 New York City
At covered New York City retail locations, Saconde will:
- post clear and conspicuous notices at customer entrances where legally required;
- accurately disclose whether customer biometric identifier information is collected, retained, converted, stored, or shared;
- and prohibit sale, lease, trade, exchange for value, or other profiting from customer biometric identifier information.
23.7 Comprehensive State Privacy Laws
Where biometric data is defined as sensitive data under an applicable state privacy law, Saconde will:
- obtain consent where required;
- permit withdrawal of consent;
- conduct required data-protection assessments;
- honor applicable access, correction, deletion, portability, opt-out, and appeal rights;
- restrict secondary use;
- and avoid unlawful discrimination.
24. COMPLIANCE AUDITS
Saconde will periodically review its biometric practices to determine:
- what Biometric Data is processed;
- where it is stored;
- who has access;
- which providers receive it;
- whether consent records are complete;
- whether retention periods are followed;
- whether deletion is technically effective;
- whether notices remain accurate;
- and whether legal requirements have changed.
Material findings must be documented and remediated.
25. TRAINING
Personnel who access, manage, develop, procure, or oversee biometric technology must receive appropriate training concerning:
- applicable laws;
- consent requirements;
- prohibited uses;
- security;
- retention;
- destruction;
- service-provider restrictions;
- incident reporting;
- and individual rights.
26. ENFORCEMENT
Violations of this Policy may result in:
- removal of access;
- corrective action;
- disciplinary action;
- termination of employment or contract;
- vendor remediation;
- contract termination;
- and legal action where appropriate.
Employees and contractors must promptly report suspected noncompliance.
27. POLICY OWNERSHIP
Saconde’s designated privacy officer, legal function, or other authorized executive is responsible for:
- maintaining this Policy;
- approving biometric technology;
- reviewing consent forms;
- coordinating rights requests;
- overseeing service providers;
- implementing deletion schedules;
- and responding to incidents.
Saconde should designate, in writing:
- the Policy owner;
- the security owner;
- the person responsible for deletion;
- and the person responsible for responding to privacy requests.
28. ANNUAL REVIEW
This Policy will be reviewed:
- at least annually;
- before implementing new biometric technology;
- after a material security incident;
- after a material change in law;
- after a significant change in processing;
- and when an audit identifies a deficiency.
29. CHANGES TO THIS POLICY
Saconde may amend this Policy to reflect changes in law, technology, services, or business practices.
A material change that expands the collection or use of Biometric Data will not be applied to previously collected information without additional notice and consent where required.
The “Last Updated” date identifies the most recent revision.
30. CONTACT
Questions, concerns, or requests regarding this Policy may be submitted to:
Saconde, LLC
Attn: Biometric Privacy
521 W 26th St, Floor 5
New York, NY 10001
United States
Email: hello@saconde.com
Website: www.saconde.com