Privacy Policy
Published November 1, 2025
On this page
This Privacy Notice explains how Ora FacePass ("we," "us," or "our") collects, uses, stores, shares, and protects information when you use our smart lock devices, mobile application, and related services (collectively, the "Services").
We've written this notice in plain language. Where US states or other jurisdictions require specific disclosures, those sections are clearly labeled below. If anything is unclear, please contact us at privacy@orafacepass.com.
Quick Summary: We collect biometric data (face, fingerprint, palm vein) only with your consent, store templates locally on your device by default, never sell your data, and let you delete it any time. State-specific rights are detailed below.
Contents
1. Information We Collect
2. How We Use Information
3. Biometric Data — Special Protections
4. How We Share Information
5. How Long We Keep Information
6. How We Protect Information
7. Your Choices and Rights
8. State-Specific Disclosures • Illinois (BIPA) • Texas (CUBI) • Washington (RCW 19.375 + My Health My Data) • California (CCPA/CPRA)
9. Children's Privacy
10. Changes to This Notice 11. How to Contact Us
1. Information We Collect
1.1 Information You Provide
Account information:
name, email address, password, phone number (optional).
Property and device information:
home or property name, device names, room assignments, and access permissions you create.
User profiles:
names and access levels for family members, guests, or other authorized users you add.
Biometric data:
face, fingerprint, and palm vein patterns you enroll. See Section 3 for full details.
Communications:
messages you send to our support team or feedback you submit.
1.2 Information Collected Automatically
Device information:
model, serial number, firmware version, battery level, and connectivity status.
Usage information:
lock and unlock events, credential type used (face, fingerprint, passcode, etc.), and timestamps.
Video and audio:
if your device's video doorbell or motion detection feature is enabled, we may capture short video clips and audio when motion or doorbell activity is detected. Live video streams are end-to-end encrypted.
App and connection data:
IP address, app version, mobile operating system, and approximate location (only when you grant permission).
1.3 Information from Third Parties
If you choose to integrate Ora FacePass with third-party services (such as voice assistants, property management platforms, or alarm systems), we may receive information from those services as needed to provide the integration. You control these integrations and can disconnect them at any time.
2. How We Use Information
We use information to:
Operate the smart lock and verify your identity at the door.
Provide, maintain, and improve our Services.
Send important account, security, and product notifications.
Respond to support requests and troubleshoot issues.
Detect and prevent fraud, abuse, and security incidents.
Comply with legal obligations and enforce our terms.
We do not use your biometric data, video, or audio for advertising, marketing, or to train artificial intelligence or machine learning models intended for use by other customers or third parties.
3. Biometric Data — Special Protections
Because biometric data is uniquely sensitive, we apply additional protections beyond what we apply to other personal information.
3.1 What We Collect
During enrollment, the device captures images of your face, fingerprint, or palm and converts them into encrypted mathematical templates. We do not retain the original images. Only the encrypted templates are stored.
3.2 Where Templates Are Stored
Biometric templates are stored locally on your Ora FacePass device in encrypted form. Templates are not uploaded to our servers or any cloud service unless you specifically enable a feature that requires cloud sync (such as sharing credentials across multiple Ora FacePass locks on the same account). When cloud sync is enabled, templates remain encrypted in transit and at rest, and we use them solely to provide the requested service.
3.3 How Templates Are Used
Biometric templates are used only to verify your identity at the lock. Each unlock attempt is matched against the stored template on the device. We do not use biometric data for any other purpose.
3.4 Your Consent
We collect biometric data only after you provide informed consent through the Ora FacePass mobile app or directly on the device. You can withdraw consent at any time by deleting your enrolled biometrics. If you do not wish to use biometrics, you can use Ora FacePass with a passcode, key fob, mobile app unlock, or physical key.
3.5 We Do Not Sell Biometric Data
We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. We do not share biometric data with third parties except: (a) to a service provider acting on our behalf and bound by confidentiality and data protection obligations consistent with this notice; (b) when required by a valid warrant, subpoena, or court order; or (c) with your explicit consent.
4. How We Share Information
We share information only in these limited circumstances:
With service providers
who help us operate the Services (such as cloud hosting, customer support tools, analytics for non-biometric data). These providers are contractually required to protect your information and use it only for the services they provide to us.
With other users you authorize
— for example, family members or guests you add to your property. They see only the information needed to use their assigned access.
For legal reasons,
when required by law, valid legal process, or to protect the rights, property, or safety of users, the public, or Ora FacePass.
In connection with a business transaction,
such as a merger, acquisition, or sale of assets. We will notify you and require the recipient to honor this notice.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
5. How Long We Keep Information
We keep information only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
Biometric data:
until you delete it from the device or app, you perform a factory reset, your account is closed, or one (1) year after your last interaction with the device, whichever occurs first.
Account information:
until you delete your account, plus a short retention period required for legal and accounting purposes.
Lock and unlock event logs:
up to 12 months by default, or as configured in your app settings.
Video and audio clips:
up to 30 days by default, or as configured in your app settings.
Support communications:
up to 3 years from your most recent contact.
When information is no longer needed, we permanently delete or anonymize it.
6. How We Protect Information
We use industry-standard technical and organizational safeguards to protect your information, including:
Encryption of biometric templates and other sensitive data at rest and in transit.
Storage of biometric templates locally on the device by default.
Access controls limiting which employees and service providers can access personal information.
Regular security reviews, vulnerability testing, and patch management.
Secure software update mechanisms with cryptographic signature verification.
We protect biometric information using the same or greater standard of care that we use to protect other confidential and sensitive information. No system is perfectly secure, but we work hard to keep your information safe.
7. Your Choices and Rights
Regardless of where you live, you can:
Access
your account information through the Ora FacePass mobile app.
Update or correct
your account information at any time in the app.
Delete
your enrolled biometrics through the app or the device Settings Menu.
Delete
your account by contacting
or using the in-app account deletion option.
Disconnect
third-party integrations.
Opt out of non-essential communications
by adjusting notification settings or unsubscribing from emails.
Residents of certain states and regions have additional rights described in Section 8.
8. State-Specific Disclosures
Illinois Residents — Biometric Information Privacy Act (BIPA)
This section applies to residents of Illinois and is provided in accordance with the Illinois Biometric Information Privacy Act, 740 ILCS 14 et seq. ("BIPA").
Biometric Identifiers and Information We Collect
Ora FacePass devices collect biometric identifiers (specifically: scans of facial geometry, fingerprint patterns, and palm vein patterns) when you enroll these credentials. We convert these into encrypted mathematical templates ("biometric information" under BIPA).
Specific Purpose
We collect, store, and use your biometric identifiers and biometric information for one purpose: to verify your identity to unlock your Ora FacePass smart lock. We do not use biometric data for any other purpose.
Written Consent
Before we collect any biometric identifier, we obtain your written consent through the enrollment flow in the Ora FacePass mobile app or on the device. By completing enrollment, you provide informed written consent to the collection, storage, and use of your biometric identifiers and biometric information for the purpose described above. You may revoke consent at any time by deleting your enrolled biometrics; revocation does not affect the lawfulness of processing before revocation.
Retention and Destruction Schedule
We will permanently destroy your biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within one (1) year of your last interaction with the Services, whichever occurs first. Local templates stored on the device are destroyed when you delete them, perform a factory reset, or the device is decommissioned.
No Sale or Profit
We do not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information.
Disclosure
We do not disclose, redisclose, or otherwise disseminate biometric identifiers or biometric information except: (a) with your consent; (b) to complete a financial transaction you requested or authorized; (c) as required by state, federal, or municipal law or ordinance; or (d) pursuant to a valid warrant or subpoena.
Standard of Care
We store, transmit, and protect biometric identifiers and biometric information using a reasonable standard of care within our industry, and in a manner that is the same as or more protective than the manner in which we store, transmit, and protect other confidential and sensitive information.
Illinois Residents: If you have questions about this BIPA disclosure or believe your rights have been violated, please contact privacy@orafacepass.com. You may also have a private right of action under BIPA.
Texas Residents — Capture or Use of Biometric Identifier (CUBI)
This section applies to residents of Texas and is provided in accordance with Tex. Bus. & Com. Code § 503.001 ("CUBI").
Notice and Consent
Ora FacePass captures biometric identifiers (scans of facial geometry, fingerprint patterns, and palm vein patterns) only after providing notice and obtaining your consent through the enrollment flow.
Purpose
Captured biometric identifiers are used solely to verify your identity at the smart lock.
No Sale
We do not sell biometric identifiers.
Limited Disclosure
We do not disclose biometric identifiers to third parties except: (a) with your consent; (b) to complete a financial transaction you requested or authorized; (c) as required by federal or state law; or (d) pursuant to a valid warrant or subpoena.
Retention
Biometric identifiers will be destroyed within a reasonable time, and in any event no later than one (1) year after the date the purpose for collecting the identifier expires (such as when you stop using the Services or delete your account).
Storage
We store biometric identifiers using reasonable care and at least as protectively as we store other confidential information.
Washington Residents — RCW 19.375 and My Health My Data Act
This section applies to residents of Washington.
Biometric Identifiers (RCW 19.375)
Ora FacePass enrolls biometric identifiers (face, fingerprint, palm vein) in a database for the commercial purpose of providing smart-lock authentication. Before enrollment, we provide notice and obtain your consent through the enrollment flow.
Use and Disclosure
We use your biometric identifiers solely to provide the authentication service. We do not sell biometric identifiers, and we do not disclose them to third parties except: (a) with your consent; (b) as needed to provide the service you requested; (c) to comply with legal obligations; or (d) pursuant to a valid warrant or subpoena.
Retention
We retain biometric identifiers only as long as reasonably necessary to provide the Services, and we destroy them when the purpose for collection has been satisfied or within one (1) year of your last interaction, whichever occurs first.
My Health My Data Act
If you use any feature of the Services that processes "consumer health data" as defined by Washington's My Health My Data Act, we will provide additional notice and obtain separate consent before doing so. As of the effective date of this notice, our standard smart-lock features do not process consumer health data.
California Residents — CCPA / CPRA
This section applies to residents of California and is provided in accordance with the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").
Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information:
Identifiers:
name, email, account ID, IP address, device serial number.
Customer records:
contact information, account details.
Commercial information:
purchase history, product registrations.
Internet activity:
app usage, device interaction logs.
Geolocation data:
approximate location (only with permission).
Audio and visual data:
video and audio captured by the device's doorbell or motion detection features.
Sensitive personal information:
biometric information used for authentication (face, fingerprint, palm vein); precise geolocation is not collected.
Sources and Purposes
We collect this information directly from you, automatically through the Services, and occasionally from third-party integrations you authorize. We use it for the purposes described in Section 2 of this notice.
Sale and Sharing
We do not sell personal information for monetary value, and we do not share personal information for cross-context behavioral advertising. We have not sold or shared the personal information of California residents in the preceding 12 months, including the personal information of consumers under 16 years of age.
Use of Sensitive Personal Information
We use sensitive personal information (biometric information) only for the purposes specified in Section 3: to verify your identity at the smart lock. We do not use sensitive personal information for any purpose that would trigger your right to limit its use under Cal. Civ. Code § 1798.121.
Your California Rights
As a California resident, you have the right to:
Know
what personal information we collect, use, disclose, and (if applicable) sell or share.
Access
a copy of the personal information we have collected about you.
Delete
personal information we have collected, subject to certain exceptions.
Correct
inaccurate personal information.
Opt out
of the sale or sharing of personal information (we do not sell or share, but you can confirm this status).
Limit
the use and disclosure of sensitive personal information (we already limit use as described above).
Non-discrimination
— we will not discriminate against you for exercising any of these rights.
How to Exercise Your Rights
To exercise any of the rights above, submit a request through:
We will verify your identity before processing the request, typically by confirming information associated with your account. You may also designate an authorized agent to make a request on your behalf; the agent must provide proof of authorization.
Response Time
We will confirm receipt of your request within 10 business days and respond substantively within 45 days. If we need more time (up to an additional 45 days), we will let you know.
Retention
Retention periods are described in Section 5 of this notice.
9. Children's Privacy
Ora FacePass is intended for use by adults. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the threshold). Adults may add children as users of the smart lock with appropriate supervision; in those cases, the parent or guardian who controls the account is responsible for managing the child's access.
If we learn that we have collected personal information from a child without proper authorization, we will delete it promptly. If you believe a child has provided us with personal information, please contact privacy@orafacepass.com.
10. Changes to This Notice
We may update this Privacy Notice from time to time. When we make material changes, we will notify you through the Ora FacePass app, by email, or by posting a prominent notice on our website. The "Last Updated" date at the top of this notice indicates when it was last revised.
11. How to Contact Us
If you have questions, concerns, or requests regarding this notice or your personal information, please contact us:
Email:
Mail:
Ora FacePass, [INSERT BUSINESS ADDRESS]
Phone:
+1 (888) 673-9899
Website:
We aim to respond to all privacy inquiries within 30 days.
— End of Privacy Notice —