Privacy Policy

Privacy Policy
Welcome to ZipID! We offer automated Form I-9 software as a service and are committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, share, and protect information in connection with our services, which are accessible via our zipidapp.com.
Personal Information: Information that you provide directly, such as your name, email address, and contact details, when you register for our services, contact customer support, or participate in surveys and promotions, and information legally required to comply with federal law for the duration set by federal law.
Biometric Data: Face images and attending metadata that optimize the protection of identity.
Usage Data: Information on how you use our services, including interaction times, features used, and pages visited within our application.
Technical Data: Information such as your IP address, device type, operating system, and browser type, which helps us diagnose technical and legal issues and optimize our service delivery.
Cookies and Tracking Technologies: We use cookies and similar technologies to track the activity on our service and hold certain information, enhancing your experience and understanding usage patterns.
- Comply with legal requirements;
- Provide, maintain, and improve services, including customer support as well as enhance security of our services,
- Communicate with you about your account or our services, including to send you updates or other essential communications;
- Conduct research and analysis to understand our user base more effectively;
- Comply with legal obligations.
Customers: Employers and any third-party services they engage to support employee onboarding or related HR functions, including to verify identity.
Service Providers: Third-party companies who perform tasks on our behalf like authenticating information, hosting, data analytics, marketing, and customer service.
Legal Obligations: If required by law or when we believe it's necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
Business Transfers: In connection with a merger, acquisition, or sale of assets. We ensure that these third parties respect the confidentiality of your data and comply with all applicable data protection laws.
We implement a range of security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. We regularly review our security practices to adapt to new risks.
We retain your personal information for as long as necessary to provide you with our services, comply with our legal obligations, resolve disputes, and enforce our agreements.
However, we do not have access to employer I-9 consoles, or expose any I-9 data to anyone but those required to have it by law.
- Employees provide explicit consent before the Form I-9 automated process begins.
- Employees provide consent that their personal information and biometric data is shared with employers and any third-party services they engage to support employee onboarding or related HR functions, including to verify identity.
- Employees approve that all fields from chosen documents are correct; employers are alerted if an employee changes from data derived directly from an ID.
- Employers are passed information collected in a fully encrypted manner, and such data is not shared but retained only for legal compliance purposes for three years from date of hire, as required by federal law. It is thereafter deleted.
- ZipID, Inc will not sell, rent, or trade Personal Information other than that required to support employer.
- ZipID collects data required by federal law.
- Our third parties, Innovatrics, who extracts ID data, and Regula, who read data that is auto-populated into the Form I-9, never retain personal or biometric data.
- We encrypt your data end-to-end, both at rest and in transit, as recommended by the National Institute of Science and Technology.
- ZipID only retains the employee data as necessary to comply with federal law. We strongly encourage employers to hold such data locally for compliance purposes. See here for more information on what a compliant paper or digital retention system is for Form I-9s.
- ZipID will retain an audit trail of your users that adjudicated a Form I-9 for audit purposes.
- ZipID uses encryption for data at standards recommended by the National Institute of Science and Technology.
- The right to access, update, or delete the information we have on you.
- The right to object to processing of your personal data.
- The right to request that we restrict the processing of your personal information.
- The right to data portability.
- To exercise these rights, please contact us at info@zipidapp.com.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and, where appropriate, through other means.
Frequently Asked Questions
Is ZipID ICE-compliant I-9 software?
Yes. ZipID is designed to satisfy all five federal electronic I-9 system requirements under 8 CFR § 274a.2, including compliant audit trails, electronic signature protocols, and secure storage standards — including the March 2026 ICE reclassification of substantive violations.
As of January 2, 2025, I-9 paperwork violations carry fines of $288 to $2,861 per form under 8 CFR § 274a.10(b)(2). Knowingly hiring unauthorized workers carries fines up to $28,619 per worker for repeat offenses. ICE audit rates in 2025 ran at least ten times higher than in 2024.
ZipID uses NIST-validated biometric facial recognition at 99.998% accuracy to match a live selfie to the photo on the new hire's government-issued ID. OCR extracts and autofills document data, and fraud detection checks for tampered, synthetic, or spoofed documents.
ZipID plans to become a certified E-Verify third-party agent by August 2026. E-Verify completion is currently part of the I-9 workflow after the employer signs the form, with ZipID toggling to E-Verify, and then data from the E-Verify case is autofilled into the Additional Information box on the I-9 form, for preservation and audit purposes.
What is NIST and why does it matter for I-9 verification?
NIST — the National Institute of Standards and Technology — is a federal agency that sets the accuracy and performance benchmarks for biometric and identity verification technologies. For I-9 compliance, NIST standards matter because they provide an independent, government-validated measure of whether a facial recognition system is accurate enough to trust. ZipID uses NIST-tested algorithms rated at 99.8% accuracy, meaning employers can be confident that the identity match on every new hire meets the highest federal standard — not just a vendor's own claim.
ZipID completes the entire Form I-9 process — including identity verification, document capture, and E-Verify — in under 8 minutes, for both remote and in-person new hires.
ZipID's 1:1 facial recognition — which matches a live selfie to the photo on a government-issued ID — is rated at 99.8% accuracy using NIST-validated algorithms. This means fewer than 2 mismatches per 1,000 verifications. The system also includes liveness detection to prevent spoofing, ensuring the selfie is from a real, present person and not a photo or deepfake.
CR — Optical Character Recognition — is technology that reads and extracts text from physical documents like government-issued IDs. ZipID uses AI-powered OCR to instantly capture and interpret data from a new hire's ID, then automatically populate the required fields on Form I-9 — eliminating manual data entry, typos, and transcription errors. Unlike basic OCR tools, ZipID's AI layer also cross-checks extracted data for logical consistency, validates security features, and flags tampered, synthetic, or spoofed documents — turning a simple document scan into a fraud detection checkpoint.
ZipID uses NIST-validated biometric facial recognition at 99.8% accuracy to match a live selfie to the photo on the new hire's government-issued ID. OCR extracts and autofills document data, and fraud detection checks for tampered, synthetic, or spoofed documents.
It is completely the employer's choice. Facial authentication can assure that a new hire is who they say they are, and the ID they present matches their live self.
This is especially important for remote workers, or industries subject to immigration fraud or economic espionage from foreign adversaries who may pose as Americans for access to proprietary information.
How long does it take to complete an I-9 with ZipID?
ZipID completes the entire Form I-9 process — including identity verification, document capture, and E-Verify — in under 8 minutes, for both remote and in-person new hires.
ZipID is an I-9 compliance and identity verification platform that combines facial recognition, OCR document capture, and fraud detection to verify new hire identities and complete Form I-9 in under 8 minutes — with a legally compliant audit trail built in. It is the only I-9 platform built by the person who helped write the federal identity doctrine behind the law.
Who built ZipID?
ZipID was founded by Janice Kephart, former counsel to the 9/11 Commission and a national security identity expert with 25 years of federal and private sector experience, as a lawyer and policy and technology identity expert. Kephart authored the federal identity doctrine and biometric entry-exit recommendations that underlie today's I-9 compliance framework. She has testified before Congress 19 times on identity-related issues, and is an I-9 expert.