Identity Verification Policy
Reading note. Identity verification is document-based and runs entirely on a verification provider's side. Tirvea keeps only the provider name, an opaque session id, and the verdict - never your documents or images. It is distinct from photo verification (Photo Verification Policy, /legal/photo-verification).
1. Purpose
Purpose. To explain how Tirvea verifies a member's identity using a government-issued identity document, why we do it, and what we store. Identity verification supports safety and integrity and reduces impersonation and fraud.
2. Scope
Purpose. To state what this Policy covers. It covers document-based identity verification through a verification provider. It does not cover photo verification (Photo Verification Policy, /legal/photo-verification) or the biometric handling (Biometric Information Policy, /legal/biometric-data).
3. Legal Basis
Purpose. To state the legal basis. We process identity-verification data on the bases in the Privacy Policy (/legal/privacy): performance of a contract and pre-contractual steps, compliance with legal obligations, and our legitimate interests in fraud prevention and safety; and consent where a check is optional. The document data is personal data; because Tirvea does not receive or store the document or images, it does not hold the associated special-category content. [Legal review required before publication - confirm the lawful bases and whether any check involves special-category data at the provider.]
4. Verification Process
Purpose. To describe the flow. When identity verification is required or offered: (1) we start a verification session with the provider; (2) you are redirected to the provider's hosted flow to complete the check (typically submitting a government-issued identity document and a selfie); (3) the provider performs the check on its side; (4) the outcome is returned to us by a signed webhook; and (5) we record the verdict and update your verification status (§8).
5. Verification Provider
Purpose. To identify the provider. Identity verification runs through a provider abstraction. The supported providers are Stripe Identity (the default), Persona, and a mock provider used only in development. The active provider is set by configuration; if no provider is configured, identity verification does not run. Each provider acts as our processor (and, for some functions, an independent controller) under its own terms and privacy notice.
6. Accepted Documents
Purpose. To explain accepted documents. Identity verification uses a government-issued identity document - typically a passport, driving licence, or national identity card. The specific accepted document types are determined by the verification provider (for example, Stripe Identity), not by a list maintained in Tirvea. [Legal review required before publication - confirm the accepted document types from the active provider's current coverage.]
7. Supported Jurisdictions
Purpose. To explain country coverage. The countries and regions in which identity verification is available are determined by the verification provider's coverage, not by a country list maintained in Tirvea. Availability may therefore vary by country and change as the provider's coverage changes. [Legal review required before publication - confirm supported jurisdictions from the active provider's current coverage.]
8. Verification Status
Purpose. To explain statuses. A verification session has one of these statuses: pending (started, awaiting your input or the provider), approved (passed), rejected (not passed), expired (the session lapsed), or manual_review (routed to a person). These are mapped from the provider's own status vocabulary.
9. Verification Badge
Purpose. To explain the badge. A successful (approved) verification records an identity-verified verdict, which shows as an Identity Verified badge. Tirvea uses two independent trust facts: Identity Verified (this Policy) and Photo Verified (the photo/face layer, Photo Verification Policy, /legal/photo-verification); they are separate and shown independently. The badge is a simple indicator and does not expose your documents or any provider detail.
10. Failure Reasons
Purpose. To explain why verification may not pass. A verification may be rejected or routed to manual review for reasons determined by the provider's check (for example, the document could not be validated, the selfie did not match, or the session expired). We receive the outcome, not your document; specific reason detail from the provider is used only to decide the outcome and is not published. You can re-attempt verification and, where a decision affects your account, appeal (§14).
11. Human Review
Purpose. To explain human review. A verification can be routed to manual review - for example, when the risk band is critical (§13) or the provider result needs confirmation. Trained reviewers decide the outcome; an appeal against an automated outcome is not decided solely by the same automated system (Appeals Policy, /legal/appeals).
12. Duplicate Identities
Purpose. To explain duplicate-identity handling. We use a duplicate-identity classification that grades evidence into severity bands to help detect the same person operating multiple identities, alongside broader duplicate and evasion detection (device and phone signals) described in the Privacy Policy (/legal/privacy) and Account Suspension Policy (/legal/account-suspension). Confirmed duplicate or evasion accounts are handled under the Account Suspension Policy. [Legal review required before publication - confirm the scope of duplicate-identity detection at identity-verification time.]
13. Fraud Prevention
Purpose. To explain fraud prevention. Identity verification is a fraud-prevention measure. It is informed by a risk engine that bands risk (low to critical); a critical band blocks automatic verification and forces manual review (§11). Verification signals contribute to detecting identity fraud, account takeover, and impersonation, as described in the Trust & Safety Policy (/legal/trust-safety).
14. Appeals
Purpose. To explain how to challenge an outcome. If verification is rejected or revoked and you believe that is wrong, you can re-attempt verification and, where a decision affects your account, appeal under the Appeals Policy (/legal/appeals). A person reviews an appeal against an automated outcome.
15. Verification Revocation
Purpose. To explain revocation. Where a verification is invalidated, found wrongful on review, or obtained by fraud, the identity-verified status is revoked and the Identity Verified badge is removed. The account is then handled under the Account Suspension Policy (/legal/account-suspension), including any re-verification requirement.
16. What We Store
Purpose. To state what we hold, minimally. In Tirvea's systems we store only: the provider name, an opaque provider session id, the verification verdict, and the identity-verified timestamp. We do not store identity documents, selfies, images, or biometric derivatives - these are handled entirely by the provider. This is the least data necessary to record that verification occurred and its outcome.
17. Retention
Purpose. To state how long we keep it. The verdict and opaque references are retained as set out in the Data Retention Policy (/legal/data-retention), which this Policy does not override. Provider-held documents and images are governed by the provider's own retention terms. On account deletion, our verification records are removed as described in the Data Retention Policy and Account Deletion Policy (/legal/account-deletion).
18. Security
Purpose. To explain protection. Identity verification is protected by webhook signature verification, opaque references, provider-side capture (so documents never enter our systems), and the safeguards in the Security Policy (/legal/security). Because we store no documents or images, a compromise of our systems does not expose them.
19. Audit Logging
Purpose. To explain audit records. Verification events and outcomes are recorded in audited records, with human actions attributed to a human actor, supporting appeals (§14), transparency, and lawful requests. Records are retained per the Data Retention Policy (/legal/data-retention).
20. Privacy
Purpose. To connect to privacy. How identity-verification data is processed is described in the Privacy Policy (/legal/privacy); your rights are in GDPR & Your Rights (/legal/gdpr). Only the verdict and opaque references are held by Tirvea; documents and images are handled by the provider under its terms.
21. Updates
Purpose. To explain changes. We update this Policy to reflect changes in our verification provider, coverage, or the law - including when we confirm the accepted documents and supported jurisdictions from the provider. We update the "Last Updated" date and take reasonable steps to communicate material changes.
22. Contact
Purpose. To tell you how to reach us about identity verification.
- Data Controller: WiseWave Limited (Company Number 762171)
- Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
- Email: info@tirvea.com
For photo verification, see the Photo Verification Policy (/legal/photo-verification); for your rights, GDPR & Your Rights (/legal/gdpr); for retention, the Data Retention Policy (/legal/data-retention).