Settings
Retention settings are legal configuration, not preferences — the ingest path enforces them at write time.
Data retention
What each venue is permitted to keep from a scanned ID
How this works. The licence number is never stored anywhere in this system — it's converted to a one-way hash at the moment of the scan, which is what makes repeat-visit counting and watchlists work without holding the identifier. Everything below controls the additional fields a venue keeps on top of that. Where a state's statute is stricter than your setting, the statute wins automatically.
Stores only the pass/fail result and an age bracket. No name, no date of birth, no exact age, no photo.
Adds exact age, issuing state, and document type. Still no name, date of birth, or photo.
Adds name and date of birth. No ID photo retained.
Retains the ID photo as well. Only for states and venue types where this is expressly permitted.
| Venue | State | Configured | In effect | Window | Legal review |
|---|---|---|---|---|---|
| Bryant Field Stadium | AL | Minimal | Minimal | 90d | No specific statute |
| The Grove Tavern | AL | Standard | Standard | 90d | No specific statute |
| Riverside Social | CA | Standard | Minimal(capped by state law) | 30d | Counsel sign-off needed |
The state policies built into Venue are a conservative starting posture drawn from published statutes. They are not legal advice, and every state a customer operates in should be confirmed by their own counsel before go-live.
Team
Compliance outranks Manager — an officer must be able to pull evidence at any venue
No team members
Devices
Device keys are shown once at provisioning and stored only as a hash
Organization
Shares only the shape of detected fakes — issuing state, template era, and the signals tripped. No patron data of any kind leaves your organization.