Privacy Policy
Wink (together with our subsidiaries and Affiliates, “Wink,” “we”, “our” and “us”) respects your privacy.
.avif)
Effective Date: 4/1/2026
This Privacy Policy explains the kinds of information we may collect, how we use and share this information, and how you can exercise your rights in relation to such information. Capitalized terms not defined in this Privacy Policy have the meaning set forth in the Wink End User Terms of Use
This Privacy Policy only applies to Personal Information that is Processed by Wink in our capacity as a “business” or other similar term under applicable data protection laws. Except as otherwise stated herein, this Privacy Policy does not apply to any uses of Personal Information by a Wink Merchant or any Personal Information that Wink Processes on behalf of the Wink Merchant pursuant to a separate customer agreement. If you are a customer of a Wink Merchant, you should check the privacy policies of the Wink Merchant to understand how they may use your Personal Information. The Wink Services may, from time to time, contain links to and from the websites of other businesses. If you follow a link to any of these websites, please note that these websites have their own privacy notices and that we do not accept any responsibility or liability for their privacy obligations. Please check their privacy notices before you submit any Personal Information to these websites.
1. Information We Collect.
“Personal Information” is any information relating to an identified or identifiable natural person. “Process” or “Processing” means any operation which is performed upon Personal Information. The types or categories of Personal Information we collect and how we collect and process it depends on the nature of the relationship you have with Wink and the requirements of applicable law. We may collect the following information:
- Information You Provide Directly to Us.
We collect Personal Information you provide directly to us, including Personal Information and transaction information when you use the Wink Services, including your account information such as name, phone number, email address, and credit card number when you create a Wink Account or a Wink Merchant Account, your contact information when you communicate with us, and information you may provide to us in connection with surveys, contests, or sweepstakes. When you communicate with Wink (via email or telephone) we collect the contents of those communications, including recording the call time, call duration, and contents of telephone calls. - Information from Other Sources.
When you make a purchase from a Wink Merchant using your Wink Account, Wink collects information your purchase such as order information, shipping information, order updates, purchase frequency, Wink Merchant account information, and any rewards or discounts applicable to your purchase. Wink may also obtain information about you from other sources, including publicly or commercially available information and through third-party partners and service providers. - Automatic Data Collection.
We may collect certain information automatically through your use of the Wink Services (including our websites), such as your Internet protocol (IP) address, Technologies including cookie identifiers and mobile advertising identifiers, mobile carrier, MAC address, IMEI, and other device identifiers that are automatically assigned to your device, browser type and language, geo-location information, hardware type, operating system, Internet service provider, pages that you visit before and after using the Wink Services, the date and time of your visit, the amount of time you spend on each page, information about the links you click and pages you view within the Wink Services, and other information about actions taken through use of the Wink Services.
- Biometric Data Collection and Consent.
When you use Wink Services that involve biometric authentication (face, palm, or voice recognition), Wink collects, processes, and stores biometric identifiers and biometric information (collectively, "biometric data"). Your enrollment in Wink's biometric authentication services is entirely optional. You may choose not to use biometric authentication and may instead use alternative authentication methods offered by the Wink Merchant.
Written Consent Requirement. Before Wink collects any biometric data from you, Wink will:
(a) Inform you in writing that biometric identifiers or biometric information is being collected or stored;
(b) Inform you of the specific purpose and length of time for which your biometric data is being collected, stored, and used; and
(c) Obtain your written consent (which may be provided electronically) before any biometric data is collected.
How You Provide Consent. You provide written consent to the collection of your biometric data when you:
- Click "I Agree," "Enroll," "Accept," or a similar acceptance button when enrolling in Wink Services through a Wink Merchant's application, website, or device;
- Complete an enrollment process that includes presenting your face, palm, or voice to a Wink-enabled device after receiving notice of biometric data collection;
- Provide an electronic signature authorizing the collection of your biometric data; or
- Otherwise affirmatively consent to the collection of your biometric data as presented to you at the time of collection by a Wink Merchant.
What Biometric Data We Collect. When you enroll in Wink's biometric authentication services, we may collect:
- Face data: Facial geometry and features extracted from images of your face
- Palm data: Palm print geometry and features extracted from images of your palm
- Voice data: Voiceprint characteristics extracted from audio recordings of your voice
How Wink Processes Biometric Data. Wink processes your biometric data as follows:
- Enrollment: You provide your face, palm, or voice through a Wink-enabled device operated by a Wink Merchant
- Template Creation: Wink extracts biometric features from your enrollment data and creates an encrypted mathematical representation called a "biometric template"
- Storage: Only the encrypted biometric template is stored on Wink's secure servers and/or on encrypted edge devices operated by Wink Merchants—Wink never stores the original image, recording, or raw biometric data
- Authentication: When you authenticate at a later time, Wink creates a new temporary template from your presented biometric data and compares it to your stored template to verify your identity
- One-Way Process: The biometric template is created using a one-way cryptographic process and cannot be reverse-engineered or used to recreate your original face, palm, or voice data
This means that even if someone gained unauthorized access to Wink's systems or a Wink Merchant's device, they could not recreate images of your face, recordings of your voice, or scans of your palm from the stored biometric templates.
Right to Decline. You are not required to provide biometric data to use a Wink Merchant's services. Wink Merchants may offer alternative authentication methods, such as passwords, PINs, or payment cards. Your decision to use or not use biometric authentication will not affect your ability to purchase products or services from Wink Merchants, subject to the Wink Merchant's own policies.
2. How Wink Uses Information
We Process Personal Information for a variety of business purposes, including:
- To Provide the Wink Services or Information Requested by You.
Wink will use your Personal Information to provide the Wink Services. For example, if you have a Wink Account, Wink will use your Personal Information to create encrypted biometric templates when you enroll in or authenticate your identity through Wink in connection with your transactions with Wink Merchants, including to (i) process payments for purchases from Wink Merchants; (ii) verify your identity to approve transactions, and monitor your online behavior to identify potentially fraudulent, prohibited or illegal transactions (including through the use of automated decision making technologies); (iii) communicate with you about your purchases, e.g. to provide shipping and returns updates; and (iv) to personalize your shopping experience with Wink Merchants. - For Administrative Purposes.
Wink may use your Personal Information for our administrative purposes, including (i) authenticating and verifying your identity, (ii) to respond to your questions, comments, and other requests for customer support, technical support, or information, including information about potential or future services; (iii) to send you SMS messages related to your account and identity verification, including login codes — you may opt out at any time by replying STOP to any SMS message; (iv) to provide you access to certain areas, functionalities, and features of the Wink Services; (v) for internal quality control purposes; (vi) if you have a Wink Account or Wink Merchant Account, to communicate with you about your Wink account and the Wink Services, including by sending emails to the email address you provide to us to verify your account and for informational and operational purposes, such as account management, customer service, or system maintenance, and changes to Wink policies; (vii) to enforce our agreements; and (viii) to generally administer the Wink Services. - To Market the Wink Services.
Wink may use Personal Information to market the Wink Services as permitted by applicable law. Such uses include (i) notifying you about offers and services that may be of interest to you; (ii) tailoring content, advertisements, and offers for you; (iii) conducting market research; (iv) developing and marketing new products and services, and measure interest in Wink’s services; (v) other purposes disclosed at the time you provide Personal Information; and (vi) as you otherwise consent. If you have any questions about our marketing practices or if you would like to opt out of the use of your personal information for marketing purposes, you can contact privacy@wink.cloud at any time. - De-identified and Aggregated Information Use.
Wink may use Personal Information and other information about you to create de-identified and/or aggregated information. De-identified or aggregated information is not Personal Information, and Wink may use such information in a number of ways, including the measurement of visitors’ interest in and use of various portions or features of the Wink Services, for research, internal analysis, analytics, and any other legally permissible purposes. - Cookies and Similar Technologies.
We, as well as third parties that provide content, advertising, or other functionality on the Wink Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Wink Services. We use Technologies that are essentially small data files placed on your device that allow us to record certain pieces of information whenever you visit or interact with the Wink Services. If you would like to opt out of the Technologies we employ on the Wink Services, you may do so by blocking, deleting, or disabling them as your browser or device permits. See our Cookie Policy for more information.
3. Sharing Your Information.
Wink does not and will never sell, lease, trade, or otherwise profit from your biometric information. Under the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), Colorado Privacy Act, and other applicable state biometric privacy laws, Wink is prohibited from selling, leasing, trading, or otherwise profiting from biometric identifiers or biometric information. Wink takes this prohibition seriously and has implemented technical and organizational measures to prevent any sale or monetization of your biometric data. Wink does not sell, rent, or share mobile phone numbers or SMS opt-in consent data with third parties or affiliates for marketing purposes.
Wink does not share biometric data with independent third parties except as expressly described in this Privacy Policy and as necessary to provide the Wink Services you have requested. As described in Section 1.5, Wink creates encrypted biometric templates that cannot be reverse-engineered to recreate your original biometric data.
Nevertheless, Wink may access, preserve, and disclose non-biometric information we store in association with you (e.g., email address, transaction history) to external parties if we, in good faith, believe doing so is required or appropriate to:
- Comply with law enforcement or national security requests and legal process, such as a court order or subpoena.
- Protect your, our, or others’ rights, property, or safety.
- Enforce our policies or contracts.
- Collect amounts owed to us.
- Assist with an investigation or prosecution of suspected or actual illegal activity.
Under such circumstances where the law, a court order or other legal process prohibits notice prior to disclosure, none shall be provided.
We may share your information with the following categories of third parties as set forth below:
- Wink Merchants.
We may share any information we receive from you with the Wink Merchant from whom you purchase or seek to purchase products or services in order to facilitate and support your transaction. Your Personal Information will also be subject to the Wink Merchant’s privacy policy. We are not responsible for the privacy and security practices of Wink Merchants. - Service Providers.
We may share any information we receive with service providers that help us provide the Wink Services. The types of service providers to whom we entrust Personal Information include service providers for: (i) the provision of the Wink Services; (ii) the provision of hosting, IT and related services; (iii) the provision of information and services you have requested; (iv) payment processing; and (v) customer service activities. - Affiliates.
Wink may share Personal Information with our Affiliates for our and our Affiliates’ internal business purposes or to provide you with a service that you have requested. “Affiliate” means any entity that, directly or indirectly, controls, is controlled by, or is under common control with Wink. - Business Partners.
Wink may also provide Personal Information to business partners with whom we may jointly offer products or services, or whose products or services we believe may be of interest to you. Wink requires our affiliates and business partners to agree in writing to maintain the confidentiality and security of Personal Information they maintain on our behalf and not to use it for any purpose other than the purpose for which Wink provided them. - Advertising Partners.
Through the Wink Services, Wink may allow third-party advertising partners to set Technologies (e.g., cookies) to collect information regarding your activities (e.g., your IP address, cookie identifier, page(s) visited, time of day). These advertising partners may use this information (and similar information collected from other websites) for purposes of delivering targeted advertisements to you when you visit non-Wink related websites within their networks. This practice is commonly referred to as “interest-based advertising” or “personalized advertising.” If you prefer that we do not share your Personal Information with third party advertising partners, you may opt out of such sharing by following the instructions in our Cookie Policy.
- Biometric Data Sharing.
Wink does not share, sell, lease, trade, disclose, or re-disseminate your biometric identifiers or biometric information to any third party except in the following limited circumstances:
(a) Wink Merchants: Wink may share biometric data with the Wink Merchant through whose application, website, or device you enrolled in Wink's biometric authentication services. This sharing is necessary to provide the authentication services you requested and is done pursuant to written agreements that require the Wink Merchant to maintain the confidentiality and security of your biometric data and comply with applicable biometric privacy laws.
(b) Service Providers: Wink may share biometric data with service providers who perform services on Wink's behalf, such as cloud hosting providers, data security providers, and technical support providers. All service providers who may access biometric data are bound by written agreements that:
- Limit use of biometric data solely to providing services to Wink
- Require the same or more protective security standards as Wink maintains
- Prohibit the service provider from retaining, using, or disclosing biometric data for any purpose other than performing services for Wink
- Require compliance with all applicable biometric privacy laws
(c) With Your Consent: Wink may share biometric data with third parties when you provide specific written consent for such sharing, either via email or any other form of digital or physical communication.
(d) Legal Obligations: Wink may disclose biometric data when required to do so by law, such as in response to:
- A valid court order, warrant, or subpoena
- A lawful request by law enforcement or national security authorities
- Legal process that compels disclosure
In such cases, Wink will verify the legal validity of the request before disclosure and will provide notice to you unless prohibited by law or court order from doing so.
(e) To Prevent Harm: Wink may disclose biometric data if Wink believes in good faith that disclosure is necessary to:
- Prevent physical harm or financial loss
- Investigate, prevent, or take action regarding suspected illegal activities
- Protect the rights, property, or safety of Wink, our users, or others
Wink will not disclose biometric data for any other purpose and will never sell, lease, trade, or otherwise profit from your biometric information under any circumstances.
- Disclosures to Protect Us or Others.
We may access, preserve, and disclose any information we have associated with you if we believe doing so is required or appropriate to: (i) comply with law enforcement or national security requests and legal process, such as a court order or subpoena; (ii) respond to your requests; (iii) protect yours’, ours’ or others’ rights, property, or safety; (iv) enforce Wink policies or contracts; (v) collect amounts owed to Wink; (vi) prevent physical harm or financial loss or in connection with an investigation or prosecution of suspected or actual illegal activity; or (vii) carry out actions that we believe are otherwise necessary or advisable. In addition, from time to time, server logs may be reviewed for security purposes – e.g., to detect unauthorized activity on our services. In such cases, server log data containing IP addresses may be shared with law enforcement bodies in order that they may identify users in connection with their investigation of the unauthorized or illegal activities. - Merger, Sale, or Other Asset Transfers.
If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, then your information may be sold or transferred as part of such a transaction as permitted by law and/or contract. - International Data Transfers.
All Personal Information collected by Wink will be transferred to and stored in the United States. By choosing to visit our website, utilize the Wink Services or otherwise provide information to us, you acknowledge that your Personal Information may be transferred to countries outside of your country of residence, including the United States, which may have different data protection rules to those of your country.
4. BIOMETRIC INFORMATION RETENTION POLICY
- In accordance with the Illinois Biometric Information Privacy Act (740 ILCS 14/), Texas Business & Commerce Code Chapter 503, Colorado Revised Statutes § 6-1-1314, and other applicable biometric privacy laws, Wink makes this Biometric Information Retention Policy publicly available. This policy establishes:
(a) A retention schedule for biometric identifiers and biometric information; (b) Guidelines for permanently destroying biometric identifiers and biometric information; and (c) Protocols for responding to data security incidents involving biometric information.
What This Policy Covers. This Biometric Information Retention Policy applies to all biometric identifiers and biometric information that Wink collects, processes, or stores, including face data, palm data, and voice data (collectively, "biometric data"). As explained in Section 1.5, Wink does not store actual images, videos, or audio recordings of end-users. Instead, Wink creates and stores only encrypted biometric templates—mathematical representations derived from your biometric data that cannot be reverse-engineered to recreate your original face, palm, or voice.
Purpose of Collection. Wink collects and processes your biometric data solely for the following purposes:
- Identity Authentication: To verify your identity when you authenticate at a Wink Merchant using biometric authentication instead of passwords, PINs, or payment cards
- Fraud Prevention: To prevent fraudulent transactions and protect you and Wink Merchants from unauthorized use of your account
- Transaction Processing: To facilitate purchases and other transactions you initiate with Wink Merchants using biometric authentication
- Service Improvement: To improve the accuracy, speed, and reliability of Wink's biometric authentication technology
Wink will not use your biometric data for any purpose other than those listed above without obtaining your additional written consent.
Who Determines Collection. Wink does not interact directly with you to collect your biometric data. Biometric data is collected through Wink Merchants (such as websites, mobile applications, or physical devices operated by retailers, restaurants, or other businesses that implement Wink Services). The Wink Merchant determines whether to offer biometric authentication as an option and presents the consent request to you on behalf of Wink. Wink processes your biometric data on behalf of and at the direction of the Wink Merchant.
Prohibition on Selling or Profiting. Wink will never sell, lease, trade, or otherwise profit from your biometric data under any circumstances. This prohibition applies regardless of whether you have consented to the collection of your biometric data. Wink is prohibited by law from selling biometric data under the Illinois Biometric Information Privacy Act, Texas Capture or Use of Biometric Identifier Act, Colorado Privacy Act, and other state laws, and Wink will not engage in any such activities.
Retention of Biometric Data. Wink will permanently destroy your biometric data when the earliest of the following occurs:
- Purpose Satisfied: When the initial purpose for collecting or obtaining your biometric data has been satisfied (e.g., you close your account with a Wink Merchant, you request deletion, or the Wink Merchant terminates its use of Wink Services);
- Individual Deletion Request: When you request deletion of your biometric data by contacting privacy@wink.cloud or through a deletion request submitted to a Wink Merchant;
- Merchant Deletion: When a Wink Merchant deletes your enrollment data from their application, terminates their agreement with Wink, or otherwise instructs Wink to delete your biometric data;
- Time-Based Retention Limit: Within the applicable time period from your last interaction with Wink Services (meaning your last biometric authentication, enrollment, or other use of Wink's biometric features), as specified below based on your state of residence:
- Illinois residents: 3 years from last interaction
- Texas residents: 1 year from last interaction
- Colorado residents: 24 months from last interaction
- All other residents: 3 years from last interaction
Expedited Deletion Upon Request. If you request deletion of your biometric data, Wink will permanently destroy your biometric data within seven (7) business days of receiving your request, unless a longer period is required by law or legal obligation (such as a pending legal proceeding or valid legal hold).
Method of Destruction. When Wink destroys biometric data, Wink uses secure deletion methods designed to make the data unrecoverable, including:
- Cryptographic erasure of encryption keys rendering encrypted biometric templates permanently unreadable
- Secure overwriting of data storage locations multiple times
- Physical destruction of storage media when appropriate
- Deletion of all copies of biometric data, including backups, within a reasonable time period not to exceed 90 days from the initial deletion
Data Security Incident Response. In the event of a data security incident that may compromise the security or integrity of biometric identifiers or biometric information, Wink will:
- Immediate Assessment: Immediately assess the scope, severity, and impact of the incident
- Containment: Take immediate steps to contain the incident and prevent further unauthorized access or disclosure
- Investigation: Conduct a thorough investigation to determine the cause of the incident and what data may have been affected
- Notification: Provide notice to affected individuals and regulators as required by applicable law, typically within the timeframes required by state data breach notification laws (often within 30-60 days of discovery)
- Remediation: Implement appropriate remediation measures to prevent similar incidents in the future
- Documentation: Document all aspects of the incident response for compliance and improvement purposes
How to Request Deletion. To request deletion of your biometric data, you may:
- Email privacy@wink.cloud with the subject line "Biometric Data Deletion Request"
- Contact the Wink Merchant through whose service you enrolled and request deletion
- Mail a written request to: Wink Inc., Attn: Legal Department - Biometric Data Deletion, 6600 Chase Oaks Blvd., Suite 150, Plano, TX 75023
When submitting a deletion request, please include your name, email address, phone number (if applicable), and the name of the Wink Merchant(s) through whose services you enrolled in Wink's biometric authentication.
State-Specific Notices.
Notice to Illinois Residents: In compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14/), Wink maintains this publicly available written policy establishing retention schedules and destruction guidelines for biometric identifiers and biometric information. Illinois residents have a private right of action under BIPA if they believe their rights have been violated. You may be entitled to liquidated damages of $1,000 for each negligent violation or $5,000 for each intentional or reckless violation, plus reasonable attorneys' fees and costs.
Notice to Texas Residents: In compliance with Texas Business & Commerce Code Chapter 503 (Capture or Use of Biometric Identifier Act), Wink will not sell, lease, or otherwise disclose your biometric identifier to a third party unless: (a) you consent to the disclosure; or (b) the disclosure completes a financial transaction that you requested or authorized. Wink will destroy your biometric identifier within a reasonable time, but not later than one year after the first date the purpose for collecting the identifier expires, except as required by law or authorized by you.
Notice to Colorado Residents: In accordance with Colorado Revised Statutes § 6-1-1314 (effective July 1, 2025), Wink maintains: (a) this written policy establishing retention schedules for biometric identifiers and biometric data; (b) protocols for responding to data security incidents that may compromise biometric identifiers or biometric data as described above; (c) security controls appropriate to the sensitivity of biometric information as described in Section 6; and (d) restrictions prohibiting the disclosure of biometric identifiers without your consent except as expressly permitted by law. Colorado residents may request deletion of biometric data at any time by contacting privacy@wink.cloud.
Notice to Washington Residents: In compliance with the Washington Biometric Privacy Protection Act (RCW 19.375), Wink obtains consent before enrolling biometric identifiers and maintains this written policy establishing retention and destruction practices.
5. How to Exercise Your Rights
You may have choices about our use and disclosure of your Personal Information:
- Direct Marketing: Email.
If you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails, and we will process your request within a reasonable time after receipt. We may also send you certain non-promotional communications regarding Wink and our services and you will not be able to opt out of those communications. - Do Not Track.
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers. - Your Privacy Rights.
In accordance with applicable law, you may have the right to: (i) request confirmation of whether we are processing your Personal Information; (ii) obtain access to or a copy of your Personal Information; (iii) receive an electronic copy of Personal Information that you have provided to us, or ask us to send that information to another company (the “right of data portability”); (iv) object to or restrict our uses of your Personal Information; (v) seek correction or amendment of inaccurate, untrue, incomplete, or improperly processed Personal Information; (vi) withdraw your consent; and (vii) request erasure of Personal Information held about you by us, subject to certain exceptions prescribed by law. If you would like to exercise any of these rights, please contact us as set forth below.
We will process such requests in accordance with applicable laws. To protect your privacy, we will take steps to verify your identity before fulfilling your request.
Rights Under State Biometric Privacy Laws.
If you are a resident of Illinois, Texas, Colorado, Washington, or another state with biometric privacy laws, you have specific rights regarding your biometric information in addition to the general privacy rights described above:
Right to Information. You have the right to request and receive information about:
- What biometric data Wink has collected about you
- The purpose for which your biometric data was collected
- How long your biometric data will be retained
- With whom your biometric data has been shared
- Whether your biometric data has been used for any purpose other than authentication
Right to Access. You have the right to request access to the biometric data Wink has collected about you. Due to the nature of biometric templates (which are encrypted mathematical representations that cannot be viewed as images), Wink will provide you with information about when your biometric data was collected, the type of biometric data (face, palm, or voice), and when it was last used.
Right to Deletion. You have the right to request deletion of your biometric data at any time, for any reason. Upon receiving your deletion request, Wink will permanently destroy your biometric data within seven (7) business days as described in the Biometric Information Retention Policy above.
Right to Opt-Out. You have the right to decline to provide biometric data. Use of biometric authentication is always optional. You may choose to use alternative authentication methods offered by Wink Merchants, such as passwords, PINs, or payment cards.
Right to Withdraw Consent. You have the right to withdraw your consent to the collection, use, and storage of your biometric data at any time. Withdrawing consent is equivalent to requesting deletion—Wink will permanently destroy your biometric data within seven (7) business days of receiving your withdrawal of consent.
Right to Notice Before Collection. Before collecting your biometric data, you have the right to receive written notice that:
- Biometric data is being collected
- The specific purpose for collection
- The length of time biometric data will be stored and used
This notice will be provided to you by the Wink Merchant through whose service you are enrolling, as described in Section 1.5.
Right to Written Consent. Your biometric data cannot be collected without your prior written consent (which may be provided electronically), as described in Section 1.5.
Illinois Residents - Private Right of Action. If you are an Illinois resident, you have a private right of action under the Illinois Biometric Information Privacy Act (BIPA) if you believe your rights under BIPA have been violated.
How to Exercise Your Biometric Privacy Rights. To exercise any of these rights regarding your biometric data, you may:
- Email: privacy@wink.cloud with the subject line "Biometric Data Rights Request"
- Mail: Wink Inc., Attn: Legal Department - Biometric Privacy Rights, 6600 Chase Oaks Blvd., Suite 150, Plano, TX 75023
- Through Wink Merchant: Contact the Wink Merchant through whose service you enrolled
When submitting a request, please include:
- Your full name
- Email address and/or phone number associated with your Wink enrollment
- The name of the Wink Merchant(s) through whose services you enrolled
- A description of which right(s) you wish to exercise
- Any additional information that will help us locate your biometric data
Wink will respond to your request within the time period required by applicable law (typically within 45 days for most requests, or within 7 business days for deletion requests).
Verification of Identity. To protect your privacy and security, Wink will take steps to verify your identity before fulfilling your request to exercise biometric privacy rights. We may ask you to provide additional information or authentication to confirm your identity before we process your request.
6. Data Retention
Wink retains the Personal Information we receive as described in this Privacy Policy for as long as you use the Wink Services or as necessary to fulfill the purpose(s) for which it was collected, provide our services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.
7. Security of Your Information
General Security Measures. We take steps to ensure that your information is treated securely and in accordance with this Privacy Policy. Wink implements reasonable technical, physical, and administrative safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, and destruction. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us. To the fullest extent permitted by applicable law, we do not accept liability for unauthorized disclosure.
Security of Biometric Information. Wink stores, transmits, and protects biometric identifiers and biometric information using technical, physical, and administrative safeguards that are the same as or more protective than the manner in which Wink protects other confidential and sensitive information, including payment card information and authentication credentials.
Technical Safeguards for Biometric Data. Wink implements the following technical security measures for biometric data:
(a) Encryption at Rest: All biometric templates are encrypted using industry-standard encryption algorithms (AES-256 or equivalent) when stored on Wink's servers and on edge devices operated by Wink Merchants. Encryption keys are stored separately from encrypted data and are protected using hardware security modules or equivalent key management systems.
(b) Encryption in Transit: All biometric data transmitted between devices, edge systems, and Wink's servers is encrypted using TLS 1.2 or higher with strong cipher suites.
(c) Template-Only Storage: Wink does not store actual images, videos, or audio recordings of your face, palm, or voice. Instead, Wink creates and stores only encrypted biometric templates—mathematical representations derived from your biometric data using one-way cryptographic functions. These templates cannot be reverse-engineered or used to recreate your original biometric data.
(d) Secure Template Creation: Biometric templates are created using proprietary algorithms that extract only the minimal feature set necessary for authentication, further reducing the risk of reconstruction.
(e) Tokenization: Where feasible, Wink uses tokenization to separate biometric templates from personally identifiable information, ensuring that biometric data cannot be linked to an individual without accessing multiple secure systems.
(f) Network Segmentation: Systems that store or process biometric data are segmented from other networks and systems, with strict firewall rules and access controls governing communication between segments.
Physical Safeguards for Biometric Data. Wink implements the following physical security measures:
(a) Secure Data Centers: Biometric data stored on Wink's servers is housed in data centers with 24/7 physical security, including security personnel, surveillance cameras, biometric access controls, and environmental monitoring.
(b) Edge Device Security: Edge devices that store biometric templates operated by Wink Merchants are required to meet minimum physical security standards, including encrypted storage, tamper detection, and secure boot processes.
(c) Access Logging: All physical access to systems containing biometric data is logged and monitored, with logs retained for audit purposes.
Administrative Safeguards for Biometric Data. Wink implements the following administrative security measures:
(a) Access Controls: Access to biometric data is strictly limited to authorized personnel who have a legitimate business need to access such data for purposes of providing and supporting Wink Services. All access is logged and monitored.
(b) Role-Based Access Control: Wink employs role-based access control (RBAC) systems that grant access to biometric data only to specific job functions that require such access, and only for the minimum time necessary.
(c) Employee Training: All Wink employees and contractors who may access systems containing biometric data receive mandatory training on biometric privacy laws, data protection requirements, and security best practices.
(d) Background Checks: Wink conducts background checks on employees and contractors who will have access to systems containing biometric data, consistent with applicable law.
(e) Confidentiality Agreements: All employees, contractors, and service providers with access to biometric data are bound by written confidentiality agreements that prohibit unauthorized use or disclosure of biometric information.
(f) Vendor Management: Service providers who may access biometric data are required to maintain security standards at least as protective as those described in this policy and are subject to written agreements that specify their security obligations.
(g) Regular Security Audits: Wink conducts regular internal security audits and assessments of systems that process biometric data, and engages third-party security firms to conduct penetration testing and vulnerability assessments on at least an annual basis.
(h) Security Incident Response: Wink maintains a written security incident response plan that includes specific procedures for responding to incidents involving biometric data, as described in the Biometric Information Retention Policy above.
(i) Data Minimization: Wink collects and retains only the minimum biometric data necessary to provide authentication services and implements automated processes to delete biometric data in accordance with the retention schedules described in this Privacy Policy.
(j) Security Updates: Wink maintains processes to ensure that security patches and updates are applied to systems processing biometric data in a timely manner, typically within 30 days of release for critical security updates.
Compliance and Certification. Wink strives to comply with applicable security standards and frameworks, which may include:
- Payment Card Industry Data Security Standard (PCI DSS) for payment-related systems
- SOC 2 Type II certification for security, availability, and confidentiality controls
- ISO 27001 information security management standards
- NIST Cybersecurity Framework guidelines
Reporting Security Concerns. If you believe you have discovered a security vulnerability in Wink Services or have concerns about the security of your biometric data, please report it immediately to security@wink.cloud. Wink takes all security reports seriously and will investigate promptly.
8. Children’s Privacy
Our services are not directed to children. If you are under the age of 16 you are not permitted to use the Wink Services. We do not knowingly collect Personal Information from children under 16. If you learn that your child has provided us with Personal Information without your consent, you may alert us at privacy@wink.cloud. If we learn that we have collected Personal Information of a child under 16, we will take steps to delete such information from our files as soon as possible and terminate the child’s account.
9. Updates to this Privacy Policy.
We may revise this Privacy Policy in our sole discretion. If we make material changes to this Privacy Policy, we will notify you as required by applicable law. We will post any Privacy Policy revisions on this web page, and the revised version will be effective immediately when it is posted. If you continue to visit our website or use the Wink Services after such changes have been made, the revised Privacy Policy will be applicable to you. If you are concerned about how your information is used, bookmark this page and read this Privacy Policy periodically.
We may revise this Privacy Policy in our sole discretion. If we make material changes to this Privacy Policy, we will notify you as required by applicable law. We will post any Privacy Policy revisions on this web page, and the revised version will be effective immediately when it is posted. If you continue to visit our website or use the Wink Services after such changes have been made, the revised Privacy Policy will be applicable to you. If you are concerned about how your information is used, bookmark this page and read this Privacy Policy periodically.
10. Additional Information for Individuals located in the European Economic Area, Switzerland, or the United Kingdom
If you are located in the European Economic Area (“EEA”), Switzerland, or the United Kingdom:
- Wink takes reasonable steps to ensure that the Personal Information we collect is reliable for its intended use, accurate, complete, and up to date. Our legal basis for collecting and using the Personal Information described in this Privacy Policy will depend on the Personal Information concerned and the specific context in which we collect it. We collect and use your Personal Information to pursue our legitimate interests, in order to enter into or perform a contract with you, with your consent, or to comply with our legal obligations. If you wish to learn more about specific legal grounds we rely on to process your Personal Information for any particular purpose (including any legitimate interests we have to process this information), please contact us as provided in Section 11.
- You have the right to lodge a complaint with the data protection authority about our collection and use of your Personal Information in relation to the General Data Protection Regulation (GDPR) and other applicable law. For more information or to submit a complaint, please contact your local data protection authority. Contact details for data protection authorities in the EEA and Switzerland are available here. Contact details for the Information Commissioner’s Office in the United Kingdom are available here.
11. Additional Information for California Residents
If you are a consumer located in the state of California, USA, we process your personal information in accordance with the CCPA. This section provides additional details about the personal information we collect and use.
- We Collect, Use, and Disclose your Personal Information
This Privacy Policy describes the personal information we may collect about you, including the categories of sources of that information. We collect this information for the purposes described in Section 4 (“How We Use Your Personal Information”) and share this information as described in Section 5 (“How We Share Your Personal Information”). Wink uses cookies, including advertising cookies, as described in our Cookie Policy. - Your CCPA Rights and Choices
As a California consumer and subject to certain limitations under the CCPA, you have choices regarding our use and disclosure of your personal information: - Exercising the right to know:
You may request the following information about the personal information we have collected about you:- The categories and specific pieces of personal information we have collected about you.
- The categories of sources from which we collected the personal information.
- The business or commercial purpose for which we collected the personal information.
- The categories of third parties with whom we shared the personal information; and
- The categories of personal information about you that we disclosed for a business purpose, and the categories of third parties to whom we disclosed that information for a business purpose.
- Exercising the right to delete:
You may request that we delete the personal information we have collected from you, subject to certain limitations under applicable law. - Non-discrimination:
The CCPA provides that you may not be discriminated against for exercising these rights.
Exercising the Right to Opt Out from a “Sale”. California residents may opt out of the "sale" of their personal information. The CCPA broadly defines "sale" in a way that may include allowing third parties to receive certain information such as cookie identifiers, IP addresses and/or browsing behavior to add to a profile about your device, browser, or you. Such profiles may enable delivery of interest-based advertising by such third parties within their platform or on other sites.
Depending on how you use the Services, we may share the following categories of information for such interest-based advertising which may be considered a sale (as defined by the CCPA): identification and demographics; device information and identifiers, such as IP address and unique advertising identifiers and cookies; connection and usage information, such as browsing history or app usage; and inference data. If you would like to opt out of Wink’s use of your information for such purposes (to the extent this is considered a sale), you may do so by contacting us at privacy@wink.cloud. - California Residents - Sensitive Personal Information (Biometric Data).
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), biometric information is classified as "sensitive personal information." California residents have specific rights regarding sensitive personal information, including the right to limit its use and disclosure.
Biometric Information We Collect. As described in this Privacy Policy, Wink may collect the following categories of biometric information from California residents:
- Facial geometry and facial recognition data
- Palm print geometry and palm recognition data
- Voiceprint and voice recognition data
How We Use Biometric Information. Wink uses biometric information only for the following purposes:
- To perform the authentication services you requested from Wink Merchants
- To prevent, detect, and investigate security incidents and fraudulent transactions
- To verify your identity for transactions you initiate
- To improve the quality and accuracy of Wink's authentication technology
Wink does not use biometric information to infer characteristics about you, for targeted advertising, or for any purpose other than those listed above.
Right to Limit Use of Sensitive Personal Information. California residents have the right to direct businesses to limit the use of sensitive personal information to only those uses necessary to provide the services requested by the consumer. However, Wink already limits its use of biometric information to only the purposes described above, which are all necessary to provide the authentication services you requested. Therefore, there is no additional limitation to request.
No Sale or Sharing of Biometric Information. Wink does not and will never sell or share (for cross-context behavioral advertising) biometric information. California residents do not need to opt out of the sale or sharing of biometric information because Wink does not engage in these practices.
California-Specific Retention for Biometric Information. California residents' biometric information is retained in accordance with the Biometric Information Retention Policy described above, which provides for deletion within three (3) years of last interaction or when the purpose for collection has been satisfied, whichever occurs first, or within seven (7) business days upon request.
Exercising Your Rights Regarding Biometric Information. California residents may exercise their rights regarding biometric information by contacting privacy@wink.cloud or using the methods described in Section 4 of this Privacy Policy. Wink will not discriminate against you for exercising your California privacy rights.
12. How to Contact Us
If you have any questions, comments, or suggestions about our privacy practices, this Privacy Policy, or if you wish to submit a request to exercise your rights as detailed in this Privacy Policy, please contact Wink by email at privacy@wink.cloud. We will address your concerns and attempt to resolve any privacy issues in a timely manner.
You may also contact us by mailing us at:
Wink Inc.
Attn: Legal Department
6600 Chase Oaks Blvd., Suite 150
Plano, TX 75023