Skip to main content
AgeRail
ProductPricingDocsContact
EnglishEspañol
Sign inSign up

Privacy Policy

Version 1.0 · effective 10 August 2026

1. Controller

This Privacy Policy describes how Lalalu Marketing SL, Travessera de Gràcia 73, 4-2, 08006 Barcelona, Spain ("AgeRail", "we", "us") processes personal data in connection with the AgeRail hosted age-verification service (the "Service").

Contact for data-protection enquiries and data-subject rights: privacy@agerail.com.

2. Who this policy covers

The Service involves two distinct categories of individuals. Processing for each category is described separately below.

  • Tenant users — people who create or administer a customer organisation account (for example portal login, billing, and API configuration).
  • End users — people who complete a verification session after a tenant redirects them to the hosted AgeRail flow.

3. Tenant users

3.1 What we process

For tenant users we process account and service-administration data, including:

  • Email address and role within a tenant organisation
  • Organisation name and configuration (redirect URLs, webhook URL, default target age)
  • Billing and prepaid-credit records (balance, ledger entries, Stripe customer and payment references, VAT and billing country where provided)
  • Transactional service email metadata delivered through our email provider
  • Records of Terms acceptance at self-serve signup where applicable
  • The campaign source, campaign name, and advertising click identifier taken from the address that opened the marketing site, stored on the account row whether or not the cookie banner was accepted. The stored campaign values are not sent to Google from our servers.

On Google sign-in those campaign values transit inside the existing sign-in cookie (agvf_tenant_oauth) for 600 seconds so they survive the authentication round trip. No new cookie is written for them, and no web-storage key is written. On every signup path they also travel as a parameter in the address of the signup page, so they appear in ordinary server request logs there for as long as those logs are kept. The campaign source, campaign name, and advertising click identifier also travel in the address across this marketing site's own internal links, so they appear in ordinary landing request logs and in the visitor's browser history, not only at the signup hop.

3.2 Purposes and legal bases

We process tenant-user data to:

  • Provide, secure, and administer the Service under the contract with the customer organisation (GDPR Art. 6(1)(b))
  • Bill for prepaid credit and keep accounting records (Art. 6(1)(b) and, where required for tax and bookkeeping, Art. 6(1)(c))
  • Communicate about the account and Service (Art. 6(1)(b); operational notices under Art. 6(1)(f) where needed to protect the Service)
  • Measure which marketing-site visits become paying tenants, by sending signup and payment events to Google Analytics (Art. 6(1)(f); you can object — see section 7)

3.3 Retention

Tenant account data is retained for the life of the customer relationship. When the account ends: (a) processing stops and the account is deactivated; (b) AgeRail-controller calibration records (if any) continue to expire automatically on their 30-day retention schedule independently of termination, with the residual provider-managed recovery window described in section 4.4 — no manual deletion step is required for that store; (c) session and transaction records hold pseudonymous flow and commercial metadata only and are retained as needed for statutory accounting and legal obligations; (d) on request via privacy@agerail.com, we provide an export of the Customer's session and billing records, and delete or anonymise non-statutory tenant account contact data from active systems. After that deletion, residual copies may remain in provider-managed database backups and, in production, point-in-time-recovery logs retained up to 7 days, for a bounded further period before they expire, during which they are unavailable for ordinary processing and are not used for any other purpose. These on-request actions are performed on request and are not an automatic anonymisation sweep. Billing and tax records are retained for as long as Spanish or EU law requires. Contact us via the route below for rights requests.

4. End users

4.1 Verification processing (biometric amnesia)

When an end user completes a verification, AgeRail estimates age from a selfie and performs a liveness check. The face image and any features derived from it for that verification are processed transiently. They are not written to persistent storage and are discarded when the verification request completes. The pass or fail result is produced automatically by software, and no person reviews the decision. If the check cannot reach a conclusive result, the end user is returned to the tenant, which may offer an alternative way to verify.

The tenant receives a signed pass or fail result. The Service does not return an estimated age or liveness score to the tenant in the verification response.

Persistent records that remain after a verification are limited to service configuration, verification status, timestamps, security records, and commercial or billing information needed to provide the Service. They contain no face images and no reusable biometric templates, and the structure of those records defines no place to store them.

4.2 Operator-only calibration scalars (carve-out)

Narrow operator-only carve-out: when calibration monitoring is enabled, AgeRail may retain per-verification pseudonymous numerical outputs for model accuracy monitoring. Those outputs are limited to values relating to age estimation, liveness, decision confidence, the configured age threshold, the classification outcome, and related non-biometric operational fields. Raw images, embeddings, face hashes, IP addresses, user agents, and other identifying data are not part of this carve-out and are not retained.

Calibration records carry a pseudonymous session reference only, which tenants cannot link back to a verification. Access is limited to authorised operator personnel. Tenants cannot read the calibration store.

Legal basis for this calibration processing is GDPR Art. 6(1)(f) — legitimate interest in operating an accurate age-verification service, detecting model drift, and maintaining the reliability of the under-age blocking decision. A balancing analysis is maintained internally for that purpose.

4.3 Roles for end-user verification data

For end-user verification data processed on a tenant's instructions, the tenant is the controller and AgeRail is the processor. That relationship is governed by the Data Processing Agreement at /dpa, incorporated into the Terms of Service. For the operator-only calibration scalars described above, AgeRail determines the means and purposes and acts as controller.

4.4 Retention of end-user related records

The face image and features derived from it are not retained after the verification completes.

Per-verification pseudonymous calibration records are retained for 30 days and then deleted. After deletion, residual copies may remain in provider-managed recovery systems for a further window of up to approximately 14 days before final deletion, during which they are unavailable for ordinary processing. That residual platform window is a property of the underlying storage service and is disclosed here rather than claimed as an immediate hard purge.

Verification session and transaction metadata used for the Service and billing is retained as needed to operate the account, resolve disputes, and meet legal obligations, and is not used to reconstruct biometrics.

5. Recipients and vendors

We use the service providers and sub-processor listed at /subprocessors to host infrastructure, process payments, and send transactional email. That list includes Google Cloud (the Article 28 sub-processor AgeRail directly engages for Controller Personal Data, which in turn engages its own sub-processors under its published register), Stripe, and Postmark (controller-side service providers).

Google Analytics is a controller-side recipient of two streams, not an Article 28 sub-processor of Controller Personal Data. The marketing-site stream is a visitor identifier written after you accept the banner. The server stream is signup and payment events under a tenant-derived identifier, or under that visitor identifier if you accepted the cookie banner on the marketing site before signing up. There is no second analytics box on the signup form. Neither stream carries biometric data, a verification session identifier, or an email address.

Calibration scalar data, when collected, is limited to operator personnel and is not made available to tenants or used as a marketing dataset.

The cookies this site may write, their purpose, lifetime and recipient, and the control that changes a stored answer, are on the Cookie Policy page.

6. International transfers

AgeRail configures the biometric and verification workloads it controls, and the storage of the data they produce, to run within the European Union. Vendor support, security, and telemetry activities incidental to those services are governed by the applicable vendor terms summarised at /subprocessors. Delivery of verification results to the Controller's own configured redirect or webhook endpoints is Controller-directed; the location of those endpoints is the Controller's choice and responsibility. Current hosting-location detail is available to customers on request under confidentiality.

Payment data is processed by Stripe under Stripe's own data-processing terms and transfer mechanisms (including the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable). Transactional email data is processed by Postmark under Postmark's own data-processing terms and transfer mechanisms (including the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable). Website-visitor analytics data and the server-side signup and payment events are processed by Google under Google's own terms and transfer mechanisms (including the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable). See /subprocessors for the per-vendor transfer summary.

7. Your rights

Depending on your role and applicable law, you may have rights of access, rectification, erasure, restriction, portability, and objection (including under GDPR Art. 21 for processing based on legitimate interests).

To exercise these rights, contact privacy@agerail.com.

Calibration records are pseudonymous and carry no name, email, or other direct identifier. We will handle an objection or erasure request covering them using the information reasonably available to identify the relevant verifications, in line with GDPR Art. 11 and Art. 12, and will delete the affected records ahead of their 30-day expiry where that is feasible. The residual provider-managed recovery window described in section 4.4 still applies after such a deletion.

End users who verified through a tenant's product should also contact that tenant for requests about the tenant's own processing of their data outside AgeRail.

You may lodge a complaint with a supervisory authority. In Spain the lead authority is the Agencia Española de Protección de Datos (AEPD).

To withdraw a stored answer to the cookie banner, use the control on the Cookie Policy page. That deletes the cookies and brings the banner back. To object to the legitimate-interest measurement of tenant activity described in section 3.2, contact privacy@agerail.com.

8. Security

We apply technical and organisational measures appropriate to the risk, including access controls on the principle of least privilege; encryption in transit; enforced location controls that stop verification services running outside their approved region; controls that prevent face images and derived biometric features from being written to persistent storage, enforced both in the structure of our records and by automated checks that block changes which would weaken them; and restricted operator-only access to calibration records.

9. Changes

We may update this Privacy Policy by publishing a new version on this page with an updated version line. Material changes will be reflected in the version and effective date shown at the top of this page.

10. Contact

Lalalu Marketing SL
Travessera de Gràcia 73, 4-2
08006 Barcelona, Spain
privacy@agerail.com

AgeRail

Hosted age verification with EU-resident processing. Selfie images are deleted after each check.

Explore

ProductPricingDevelopers

Contact

EmailSign in
© 2026 AgeRail
PrivacyLegal
AgeRail is a service provided by Lalalu Marketing SL, registered at Travessera de Gràcia 73, 4-2, 08006 Barcelona, Spain. VAT: ESB16899015. EU-resident verification · Selfie images are not stored