Bad Lighting? Ticketmaster Keeps Your Face 3 Years. A Good Selfie? 60 Days.
Say you're buying concert tickets. Ticketmaster asks you to scan your face and hold up your ID. Your camera glitches, or the lighting in your kitchen makes you look like a suspect in a true crime documentary, and the check fails. Here's the part nobody tells you: that failed selfie doesn't just disappear. It can sit in a database for three years. If the check had worked? Gone in 60 days.
Ticketmaster's face-check partner deletes your data in 60 days if your identity check passes — but keeps it for 3 years if it fails, and nobody's explained why the punishment for a bad camera angle is 18 times longer than the reward for success.
Let's slow down on that math for a second, because it's genuinely strange. TechTimes reported that Ticketmaster's identity verification runs through a third-party provider, which uses your phone camera to confirm you're a real, live human (not a photo of a photo — that's what people in this industry politely call a "liveness" check, but really it's just "prove you're not holding up a picture of your face") and then compares that live scan to your government ID.
When it works, your data — your face, basically — is wiped in 60 days. When it doesn't work, it can stick around for three years. That's not a small gap. That's the difference between "we deleted the thing that identifies you" and "we're keeping this file open long enough to see two presidential elections go by." This article is part of a series — start with Biometric Binding Id Verification Explained.
Why the "Failed" Pile Is the One to Worry About
Here's the thing that should bug you: a failed check doesn't mean you did anything wrong. It could mean your ID photo is a decade old and you grew a beard. It could mean your phone camera is garbage. It could mean the app hiccupped. Or — sure — it could mean someone actually was trying to pull a fast one with a stolen ID. The problem is the system doesn't seem to separate "honest mistake" from "attempted fraud" before deciding how long to keep your face on file. Everyone who fails, for any reason, gets thrown into the same three-year bucket.
Compare that to how identity checks are supposed to work under the federal government's own rulebook. The National Institute of Standards and Technology — NIST, the agency that literally writes the technical standards companies point to when they want to look responsible — requires that companies document their retention periods and be able to publicly justify why they're keeping biometric data as long as they are, especially when there's no easy way for the person to ask for it to be deleted. Ticketmaster has published the retention windows — 60 days versus three years is right there for anyone to read. What's missing is the "why." Why three years specifically? Why not six months? Why not one year? Nobody's saying.
The distinction between successful and failed retention periods has fueled privacy concerns among customers, particularly given that the identity verification process has generated notable pushback from ticket buyers concerned about the amount of sensitive personal data being requested. — reporting from TechTimes
The Fraud Argument (And Why It's Only Half the Story)
Now, to be fair to Ticketmaster and its provider for a second — because it's easy to just be outraged and skip the nuance — there's a real argument buried in here. Ticket scalping and resale fraud cost the industry serious money every year, and if the same person keeps trying to buy tickets under fake or stolen identities, a company would want a record of that pattern. That's not crazy. Comparing a new failed attempt against old failed attempts is a genuine security tool, similar in spirit to concerns raised elsewhere about long-retention biometric fraud databases in other industries, like tax verification. Previously in this series: That Prove Youre 18 Pop Up One Version Forgets You One Keeps.
But here's where it falls apart: that logic only justifies keeping data on people who were actually attempting fraud. It does nothing to explain why someone whose check failed because of bad lighting gets lumped into the same three-year holding pen as someone running an actual scam. If you can't tell the difference between "camera glitch" and "criminal," you shouldn't be treating both cases identically. That's not fraud prevention. That's just... hoarding data and calling it security.
Why This Matters
- ⚡ The punishment doesn't fit the "crime" — a bad lighting condition or an old ID photo can land you in the same long-retention bucket as an actual fraud attempt, with no way to tell the two apart from the outside.
- 📊 Disclosure isn't the same as justification — Ticketmaster published the two timeframes, but publishing a number isn't the same as explaining why that number is fair or necessary.
- 🔮 This is becoming the industry norm — other sectors, including tax and financial verification, are experimenting with similar multi-year retention for "failed" biometric checks, meaning this pattern could spread far beyond concert tickets.
- 🧾 You likely can't see or challenge it — there's no clear, easy path for someone to find out if their failed check landed them in that three-year file, let alone get it deleted early.
What You Can Actually Do About This
If you've ever wondered whether a photo, a video, or a "verified" profile online is really what it claims to be, that's exactly the question this whole industry exists to answer — and honestly, that's a good thing when it's done right. The problem isn't that companies check identities. It's that once they've checked yours, you have almost no visibility into what happens next.
So here's one concrete thing worth doing: before you ever do a face scan for any company — ticket sites, banking apps, whatever — search for their "biometric privacy notice" or "biometric privacy policy" (Ticketmaster actually has one posted publicly). Look specifically for two numbers: how long they keep your data if the check succeeds, and how long they keep it if it fails. If those two numbers are wildly different — like 60 days versus three years — and there's no plain explanation for the gap, that's your signal to ask questions before you scan your face into their system. A company that can tell you exactly why should get more trust than one that just tells you what. Up next: Your Real Id Can Still Be Used To Steal 47 Billion Heres The.
The Part That Should Actually Worry You
Here's where it gets interesting: nobody's tracking whether these three-year fraud files actually catch repeat fraudsters, or whether they're just digital lint traps — full of harmless people's faces, sitting there because deleting data is apparently harder than collecting it. If Ticketmaster and its provider wanted to prove this system works, they could publish numbers: how many of those three-year retained faces actually turned out to be repeat fraud attempts versus honest mistakes. They haven't. And until they do, the three-year window looks less like a security measure and more like a company deciding that "we might need it later" is reason enough to keep your face on file longer than most people keep their car.
The number that should worry you isn't 60 days — it's three years. A technical glitch shouldn't cost you 18 times longer data retention than a smooth, successful check, and right now, nobody's required to explain why it does.
Think about that for a second: the version of you that fails — tired, badly lit, holding your phone at a weird angle at 11pm trying to snag concert tickets before they sell out — gets remembered longer than the version of you that succeeds. If that's not a design flaw, someone owes the rest of us an explanation for why it's a feature.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
That Job Form Asked About Your Mom's Health. In Illinois, That's a $15,000 Question.
Illinois employers are getting sued over a 25-year-old law nobody paid attention to — and it's not about your face or your fingerprint. It's about your family's medical history.
biometricsA Computer Can Now Kill Your Mortgage — And You Get 60 Days to Ask Why
A company most people have never heard of just bought another company most people have never heard of — and the deal could decide whether your mortgage or benefits application sails through or stalls out.
biometricsYour Stolen Credit Card Gets Replaced by Friday. Your Stolen Face Never Does.
Face-payment tech is being sold as the next tap-to-pay. But your face isn't a card number — you can't cancel it and get a new one. Here's what to actually ask before you say yes.
