Revolut Wants Your Face At The Coffee Counter

The biometric bargain arrives just after Revolut’s latest customer data scare.

If you’re tired of censorship and surveillance, subscribe to Reclaim The Net.

As the digital rights and privacy community is well aware, biometric data, especially when used as part of digital ID and online age verification schemes, is a Pandora’s box. And now, it’s biometrics for your coffee.

UK customers of digital bank Revolut who have an account and live in or plan to visit London, can “celebrate” the launch of the bank’s facial recognition-based payments by having a speciality coffee at one of three Kiss the Hippo cafes in the city for 1 pound.

The offer is valid for three days, from 24 to 26 September, and the coffee is not the only thing customers will be giving Revolut – they will also be providing their face biometrics. The offer is available to those who opt in through the Revolut app, and at the till, their face will be matched against “the selfie ID checks that the customer completed when first signing up to Revolut.”

This is how the bank describes the process in its press release, adding that the pilot “will expand the firm’s payment ecosystem into facial recognition checkout, unlocking a new revenue stream for the company.”

Meanwhile, the cafes will be equipped with Revolut’s new point-of-sale system, and merchants are incentivized to join the scheme as they will pay 0% processing on every Pay with Smile transaction. On top of that, the Revolut Register till is sold to them at half price, 349.50 pounds plus VAT, until 31 December 2026.

Revolut says that independent venues spend an average of 875 pounds a month on processing and infrastructure, while pubs and bars spend over 950 pounds, and terminal outages cost them 2,495 pounds a year.

“Bank grade security” is how Revolut advertises its new product, and among the features listed is this: “Authenticates transactions with end-to-end encryption managed inside the Revolut app and personal data never stored by merchants.”

This is true, but it may also be misleading, as it omits the fact that the merchant doesn’t need to store anything because it’s the bank that does. And that’s the entity that customers should logically trust the least, given the way they handle sensitive information.

Word of the bank’s last data leak reached its customers on 11 September, when Revolut disclosed that it had handed customer data to an “unauthorized third party” that sent an email from a real government domain, which the bank said it believed was genuine.

The data included names, dates of birth, addresses, account numbers, transaction histories, copies of government-issued IDs, and onboarding verification selfies.

Revolut said that the derived biometric face data was not leaked – but the selfies were.

Now, Revolut customers who take part in the new scheme will be providing the bank with yet more photographs of their face, which will be stored as a “secure copy of the original transaction photo” that is uploaded to Revolut’s “internal cloud systems” and kept as “a fallback safety measure to protect you and investigate potential fraud or payment disputes.”

This is according to the Pay with Smile Privacy Notice, which explains what data is collected, how it is used, and how long it is kept. The notice reveals that while the “temporary facial embeddings” are deleted after they are used once to authenticate a transaction, the photograph itself is kept “in line with Revolut’s applicable data retention policies.”

Those are spelled out in the Customer Privacy Notice, which says that data is kept “for as long as necessary to achieve the original purpose we collected it for” and “where we have a legitimate interest in doing so (for example, to manage our business risks or to defend legal claims).”

For UK customers the same notice sets a general ceiling of seven years after the business relationship ends, and longer where there is a legal reason to hold on to it.

The legal basis for collecting and processing the data is also explained, and it’s interesting to note that while “Verifying your identity at checkout” and “Security and liveness checks” run on “Explicit consent,” “Fraud prevention, dispute handling and service security” and “Diagnostic and troubleshooting: understanding how you use PWS to allow us to carry out research and analytics” run on “Legitimate interests.”

In other words, customers can opt in to the face match, but not out of the bank storing their photographs or using their data for research and analytics.

If a customer wants to opt out of the scheme, they can do so by withdrawing consent, which “permanently deactivates PWS and triggers the immediate deletion of your biometric template from our relevant database.”

However, Revolut makes no promise that the photographs that have already been uploaded will be deleted. Customers can also “freeze” their Pay with Smile account, which will temporarily stop face-match payments but keep all their data stored in the system.

Explore more on these topics