This page sets no cookies, runs no JavaScript and loads no analytics. View Source and check.
Someone asked to see your ID and read the machine-readable part of it — the barcode on the back of a driver's licence, or the chip in a passport. This page is the complete list of what that check kept.
It kept no name, no date of birth, no address, no document number and no photo. No image of your ID was saved or sent.
This is the whole row. The names in grey are the actual column names in the record, so you can see this is the list itself and not a summary of it.
ageInYears — 27, never a birthdayjurisdictionissuingCountrydocumentTyperealIdCompliance — what the card states about itself, never our opinion of itminimumAgeVerifiedcheckOutcome, failedCheckTypes, confidenceScoreresult, decision, rejectionReasonpassback — see belowwasOnGuestListscannedAt, and the device's own clock reading claimedScannedAt, scanTimestampFlagmethod — barcode, passport chip, or a mobile IDvenue, device, staff, member — facts about the business, not about yousignature, id — a seal, so the venue cannot quietly edit this record laterThat is the row. There is no line on it with your name in it.
Not kept
Because the barcode on the back of your licence contains everything printed on the front, and the person checking has to see that the card is yours. Your name, your date of birth and the expiry are held in the phone's memory for the few seconds that screen is up, and are never written down.
In the shipping app that screen sits in a protected layer — it cannot be screenshotted, screen-recorded or mirrored, even by the person holding the phone. When the screen goes, it is gone.
Sometimes, and only for a while. The scan may also run the machine-readable part of your document through a one-way scramble that produces a fixed string of characters. The venue's system scrambles that again with a secret belonging to that business and stores the result on a timer, then deletes it.
It can answer exactly one question: has this same card already been scanned here tonight? That is how a door notices an ID handed back over the fence to a friend. It cannot answer who you are, where else you have been, or whether you were here last week.
Two things we would rather say than have you work out.
The code is not reversible, but it is checkable. Someone who already had your card in their hand, plus that business's secret, plus its database, could confirm that this card was scanned there. They would have to start with your card — it cannot be run backwards.
The secret belongs to the business, not to the individual venue. If a business runs several venues, the same card produces the same code at all of them, so for those few hours it can tell that one card was seen at more than one of its own doors. A different company's venue produces a completely different code, and the two cannot be lined up.
Some venues have this switched off, and in some places it is off by default because the law there says so. Where it is off, no such code is made or kept.
And the uncomfortable part, because you would find it anyway: where it is off, the app on the door still calculates that code on the phone and sends it with the scan. The server does not write it down and does not compare it to anything — it is gone when the request finishes. We are telling you because the alternative is a promise with a hole in it.
Two details that only matter if they apply to you. A passport's code is made from the document number and date of birth rather than from a barcode. And an ID held in Apple Wallet produces no code at all — your phone tells you the document number will not be kept, and making a code out of it would contradict that.
The venue's managers. An inspector or regulator, if the venue exports its log. Then it is deleted automatically — each venue sets its own retention period, and the venue can tell you theirs.
We do not sell it. There is no ad network in this product and no third party gets a copy. If police ask the venue for its records, the venue has what you have just read: times, ages, outcomes. There is nothing in it with your name on it.
Anonymous usage and crash events — which buttons get used, what broke — never linked to anyone scanned. We list what we do collect because a page that only lists good news reads as marketing.
And: our web server saw a request for this page, the way every website does. We cannot connect it to any scan and could not if we wanted to. The address on that sign is printed once and is identical for everyone who scans it. There is no per-visit link and the app never makes one.
Five lists in our code name every field we sign or export, and a sixth names twenty-five words that must never appear in them: dob, firstname, licensenumber, ssn, streetaddress and twenty more. Those checks run as the server boots. If one of those lists ever gains a field whose name matches, the server throws and does not come up — not a policy someone has to remember, a crash.
What it does not do is scan the database for you. A new column that nobody adds to those lists would boot fine. It is a backstop on what we sign and export, not a magic detector.
Most pages like this have a box where you look up your record. This one cannot have one. There is no name column to match you on, no document number to search, and no way for us to find the scan you are thinking of.
If you asked us to delete your record, we could not find it. That is the whole design, and the missing box is the proof — and it is also the price.
For anything the venue keeps, ask the venue. They are the only ones who can answer that.
For the scanner itself, write to support@checkidapp.com and a person will answer. If you believe a venue has got this wrong, ask them first; after that, your state's liquor authority or attorney general is the body that licenses them.
Everything above about our software is something we are telling you about ourselves. Naming a file in our code is not the same as an audited binary, and the honest limit is that this chain bottoms out in trusting us about which code is running. The state laws and Apple's Wallet sheet are the only parts of this page that come from anyone else. If that is not enough for you, it should not be.