ArmourID Privacy Notice
Effective Date: May 29, 2026
Part I — General Privacy Notice | Part II — Consumer Health Data Privacy Notice | Exhibit A — Biometric Data Retention and Destruction Policy
Part I — General Privacy Notice
1. About This Privacy Notice
ArmourID LLC (“ArmourID,” “we,” “us,” or “our”) provides technology tools that support identity verification, document management, eligibility workflows, regulatory or participation-related requirements, and controlled data sharing among authorized users and organizations.
This General Privacy Notice (this “Notice”) explains how ArmourID collects, uses, discloses, and protects personal information when individuals and organizations use our website, platform, account features, mobile and web interfaces, APIs, and related services (the “Services”).
Because some information processed through the Services may include health-related information, biometric information, or information about minor athletes, this Notice also includes additional disclosures for certain laws and data types, including consumer health data and biometric information. This Notice should be read together with the ArmourID Terms of Service and any consent, authorization, or disclosure form presented through the Services.
2. Personal Information We Collect
“Personal information” means any information related to an identified or identifiable natural person, subject to applicable data protection laws. We may collect the following categories of personal information, depending on the nature of your interactions with us. Note that the specific personal information we collect about you may not include all the examples listed:
- Account and Contact Information: Name, email address, phone number, mailing address, username, password, account settings, and communication preferences.
- Identity Verification Information: Date of birth, government-issued identification documents, ID numbers, document images, photographs, liveness-check results, facial comparison data, and related verification records. See Section 9 (Biometric and Identity Verification Information) and Exhibit A (Biometric Data Retention and Destruction Policy) of this Notice for additional disclosures about biometric and identity verification data.
- Fighter, Athlete, or Profile Information: Name, ring name, discipline, weight class, height, fight record, gym or team affiliation, region, licensing status, eligibility status, suspension status, combat sports license numbers, state or jurisdiction of licensure, discipline, event participation history, and other information used to support fighter identity, readiness, matchmaking, roster management, event planning, or regulatory workflows. Depending on the information you provide or the features used, this may also include demographic or profile details such as date of birth, gender, nationality, country of citizenship, or similar information relevant to identity verification, eligibility, licensing, or regulatory requirements.
- Medical and Health-Related Information: Bloodwork status, lab results, medical exams, physicals, imaging records, ophthalmological or neurological records, vaccination or immunization records, physician letters, medical clearance documents, injury records, suspension-related medical records, drug testing or anti-doping status where provided by testing authorities or authorized organizations, medical expiration dates, and similar health-related documentation or status information. See Part II (Consumer Health Data Privacy Notice) for additional disclosures about consumer health data.
- Eligibility, Compliance, and Regulatory Workflow Information: Documentation status, missing or expired requirement flags, commission or sanctioning body requirements, event packets, bout lineups, event submissions, approval workflows, licensing or clearance status, suspension information, audit logs, status updates, and other information generated or used to support eligibility, participation, medical clearance, event planning, regulatory review, or compliance workflows.
- Organization and Partner Information: Business contact information and account information for promotions, gyms, training facilities, commissions, sanctioning bodies, brands, sponsors, and other organizations that use or interact with the Services. This may include organization name, legal entity name, jurisdiction of formation, business address, primary contacts, titles, email addresses, phone numbers, role-based account permissions, event records, roster information, billing information, and related account administration information.
- Communications Information: Messages, support inquiries, emails, text messages, platform notifications, in-platform messages, message metadata, recipient information, communication preferences, and records of communications with us or through the Services.
- Device, Usage, and Technical Information: IP address, device type, browser type, operating system, approximate location, unique device identifiers, log data, session information, pages or screens viewed, features used, documents uploaded or viewed, verification requests initiated, API call logs, endpoint activity, response status, error logs, crash reports, role-based access logs, and similar analytics, security, diagnostic, and platform interaction information.
- Payment or Billing Information: Billing contact details, where applicable. Payment card information is processed by a third-party payment provider and is not stored by ArmourID.
3. How Personal Information is Collected
We may collect the personal information identified above from the following sources:
- Directly From You. We collect information that you provide when you create an account, complete a profile, upload documents, submit intake forms, respond to prompts within the platform, make a payment, or contact us for support. This is the primary source of medical, eligibility, and identity information on the platform.
- Automatically. When you use the Services, we automatically collect device and usage data such as IP address, browser type, device type, operating system, pages visited, features used, session duration, and log data. This information is collected through cookies, log files, and similar technologies. See Section 10 (Cookies and Tracking Technologies) for more detail on cookies.
- From Third Parties. We may receive information about you from third-party identity verification providers (for example, liveness check or document scan results), from athletic commissions or sanctioning bodies in connection with a regulatory workflow, and from organizations such as gyms or promotions that use the platform and submit information on your behalf. We only accept third-party submissions for your account where you have authorized the relevant organization to act on your behalf, or where we are required or permitted by law to receive the information.
- Created By Us. We collect information about you that we create, such as credentials for access to the Services, or inferences generated from other information we collect.
- Service Providers. We collect information about you from certain service providers that provide information to help us provide the Services and run our business.
- Affiliates. We receive information from the companies within our family of companies and affiliates as a normal part of conducting business and performing the Services.
4. Sensitive Personal Information Collection and Use
Some information we collect is classified as “sensitive personal information” (“SPI”) under California law (California Consumer Privacy Act (CCPA), as amended) and analogous state laws.
We use and disclose sensitive personal information only for purposes permitted by law, including to provide, operate, and maintain the Services; verify identity; assess eligibility; support regulatory and compliance workflows; prevent fraud; maintain account and platform security; authenticate users; process transactions; provide customer support; comply with legal obligations; and support our ordinary business operations.
We do not use or disclose sensitive personal information for targeted advertising, cross-context behavioral advertising, to build advertising profiles, or for the purpose of inferring characteristics about individuals.
California law provides residents with the right to limit certain uses and disclosures of sensitive personal information. However, based on our current practices, ArmourID does not use or disclose sensitive personal information in a way that is subject to this right. Specifically, ArmourID uses and discloses sensitive personal information only for the limited purposes described above and otherwise permitted by California law. Therefore, ArmourID does not currently offer a separate “Limit the Use of My Sensitive Personal Information” right or link.
If our practices change and we use or disclose sensitive personal information for purposes that are subject to the California right to limit, we will update this Notice and provide a method for California residents to exercise that right as required by law.
5. How Personal Information is Used
In accordance with applicable law, we may use personal information for the following purposes:
- Business Operations and Service Improvement. To operate, evaluate, maintain, and improve our Services, systems, workflows, user experience, internal processes, and business operations.
- Account, Profile, and Platform Administration. To create, verify, maintain, secure, and administer your account, profile, and use of the Services.
- Identity Verification and Fraud Prevention. To verify your identity, authenticate users, prevent fraud, detect impersonation, and support the integrity and security of the Services.
- Eligibility and Regulatory Workflows. To store, organize, review, and process documents, medical records, health-related information, consent forms, eligibility steps, and other information needed to support eligibility, licensing, regulatory, compliance, or similar workflows.
- Documentation and Recordkeeping. To generate, store, and maintain reports, disclosures, documentation alerts, expiration notices, forms, summaries, and other records related to your account, participation, eligibility, compliance status, or use of the Services.
- Third-Party Integrations and Authorized Recipients. To allow you or authorized users to share information with athletic commissions, promotions, gyms, sanctioning bodies, regulators, service providers, teams, or other authorized recipients as part of the Services. ArmourID does not use medical documentation, consumer health data, biometric information, government identification documents, account credentials, or other highly sensitive personal information for sponsor, brand, or commercial partner purposes unless you have provided specific, documented authorization and the use is permitted by applicable law.
- Service Delivery and Support. To provide, operate, maintain, improve, troubleshoot, and support the Services, including responding to inquiries, providing customer support, and communicating with you about your account or use of the Services.
- Communications. To send service-related emails, texts, messages, alerts, reminders, platform notices, and other communications related to your account, profile, eligibility, documentation, payments, events, or use of the Services.
- Payments and Transactions. To process payments, transactions, subscriptions, fees, refunds, credits, and related billing, accounting, tax, and financial administration.
- Security, Monitoring, and Abuse Prevention. To monitor use of the Services; detect, investigate, and prevent fraud, misuse, security incidents, technical issues, policy violations, and violations of the ArmourID Terms of Service or other applicable terms.
- Legal, Regulatory, and Contractual Compliance. To comply with applicable laws, regulations, legal process, regulatory obligations, contractual obligations, law enforcement requests, and internal compliance requirements.
- Corporate Restructuring. We may use your personal information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
- With Notice or Consent. For other purposes disclosed to you when we collect your personal information or with your consent.
6. Disclosures of Personal Information
ArmourID does not “sell” personal information or “share” personal information for cross-context behavioral advertising, as those terms are defined under the CCPA and similar state privacy laws. We also do not use or disclose personal information for targeted advertising or to build advertising profiles.
We may disclose personal information in the limited circumstances described below. These disclosures are made to provide, operate, secure, and improve the Services; support eligibility, documentation, and regulatory workflows; comply with legal obligations; complete transactions; or as otherwise directed or authorized by you.
With Athletic Commissions, Regulatory Bodies, and Authorized Recipients.
We may disclose personal information, including eligibility information, medical or health-related documentation, identity information, profile information, records, approvals, and related information, with athletic commissions, regulatory bodies, sanctioning bodies, promotions, gyms, training facilities, teams, or other authorized recipients when you direct or authorize us to do so, when needed to provide the Services, where necessary to support eligibility, licensing, medical clearance, compliance, event participation, or regulatory workflows, or where required or permitted by applicable law, regulation, agreement, or regulatory process. We limit these disclosures to the personal information reasonably needed for the applicable service-related, eligibility, compliance, or regulatory purpose.
With Promotions, Gyms, Organizations, and Other Service Participants.
We may disclose profile information, roster information, eligibility status, documentation status, approvals, and related information with promotions, gyms, training facilities, organizations, or other participants in the Services where requested or authorized by you, necessary to provide the Services, or permitted by applicable law. We do not disclose full medical documentation to promotional users or other non-regulatory recipients unless authorized, directed, necessary to provide the Services, or legally required.
Sponsors, Brands, and Commercial Partners.
ArmourID may support partnerships, sponsorship opportunities, or other commercial relationships involving fighters, gyms, promotions, brands, or sponsors. ArmourID does not disclose medical documentation, consumer health data, biometric information, government identification documents, account credentials, or other highly sensitive personal information to sponsors, brands, or other commercial partners for their own marketing or commercial purposes unless the individual has provided specific, documented authorization and the disclosure is permitted by applicable law. Where ArmourID facilitates a sponsor, brand, or commercial partner interaction, ArmourID will limit the information disclosed to what is reasonably necessary for the authorized purpose.
With Service Providers.
We may disclose personal information to vendors and service providers that help us operate the Services, including hosting providers, identity verification providers, communications providers, analytics providers, payment processors, security providers, customer support providers, and other operational vendors. These providers are permitted to use personal information only to provide services to ArmourID or as otherwise permitted by law, and they are prohibited from using personal information for their own purposes.
With Our AI Document-Analysis Service.
When you upload a document or image for verification (for example, a medical record, government identification, or other eligibility document), ArmourID transmits that file to a third-party AI document-analysis service provided by Amazon Web Services (AWS) — specifically Amazon Bedrock and Amazon Textract — acting as our processor, to classify, extract, and validate the document’s information for eligibility and compliance review. The data shared for this purpose is limited to the document or image you upload and information derived from it. This provider is contractually permitted to process the data solely to provide document-analysis services to ArmourID, is prohibited from using it for its own purposes, and does not sell it or use it for advertising. The app discloses this sharing and obtains your consent before any document is sent to this service. ArmourID does not use this service, or any artificial intelligence, to make or substantially replace human decisions about your eligibility, medical clearance, licensing, or participation (see Section 8).
With Our AI Assistant.
The Services include an AI-powered assistant that answers your questions about your fighter status, documents, events, and related topics. When you send a message to the assistant, ArmourID transmits your message, together with relevant context from your account, to a third-party AI service — Anthropic’s Claude models, accessed through Amazon Web Services (Amazon Bedrock), with OpenRouter as a fallback provider — acting as our processor, to generate a response. The data shared for this purpose is limited to the messages you send and the account context needed to answer them. These providers are contractually permitted to process the data solely to provide the AI assistant service to ArmourID, are prohibited from using it for their own purposes, do not sell it, and do not use it to train their own models except as permitted under our agreements with them. The app discloses this sharing and obtains your consent before your messages are sent to this service. ArmourID does not use this service, or any artificial intelligence, to make or substantially replace human decisions about your eligibility, medical clearance, licensing, or participation (see Section 8).
For Safety, Security, Legal, or Compliance Reasons.
We may disclose personal information if reasonably necessary to comply with law, legal process, regulatory obligations, or contractual obligations; protect the rights, safety, and security of ArmourID, users, or others; prevent, detect, or investigate fraud, misuse, security incidents, or technical issues; enforce our Terms of Service or other applicable terms; or respond to lawful requests from courts, regulators, law enforcement, or other authorities.
In Connection with Business Transactions.
We may disclose personal information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, including during due diligence and transition planning. If a business transaction occurs, we will take reasonable steps to ensure the recipient handles personal information consistently with this Notice or as otherwise required by law.
With Notice or Consent.
We may disclose personal information for other purposes disclosed to you at the time of collection, with your consent, or as otherwise directed or authorized by you.
7. Authorizations and Revocations
The Services allow you to authorize ArmourID to share specific information with specific recipients. An authorization will identify: (1) the recipient; (2) the type of information to be shared; (3) the purpose of the sharing; and (4) any applicable expiration date or revocation process.
You may revoke an authorization through the platform where available, or by emailing us at info@armour-id.com. We will process revocation requests within 10 business days. Revocation applies prospectively — it does not affect disclosures that occurred before we received and processed your revocation request.
Some regulatory authorizations may be required by an athletic commission or sanctioning body as a condition of competition or licensure. ArmourID does not control those external requirements, but we will only share information to the extent of your documented authorization or as required by applicable law.
8. Automated Tools, AI Features, and Your Rights
ArmourID may use automated tools or software features to help provide and administer the Services. For example, these tools may help compare document dates against event or eligibility requirements, flag records that appear incomplete or inconsistent, generate alerts or reminders, organize information, route records for review, or support administrative workflows.
These tools are designed to support ArmourID’s Services and assist human review. They do not make final eligibility, medical clearance, licensing, participation, event approval, account status, or other similar decisions about you. Those decisions are made by ArmourID, athletic commissions, regulatory bodies, promotions, organizations, medical providers, or other authorized recipients, as applicable, based on their own review, requirements, and decision-making processes.
ArmourID does not use automated tools or artificial intelligence to make decisions that produce legal or similarly significant effects about you, and ArmourID does not use automated tools or artificial intelligence to replace or substantially replace human decision-making in connection with eligibility, medical clearance, licensing, participation, or similar determinations.
Because ArmourID does not currently use automated decision-making technology in a way that is subject to California or similar state automated decision-making opt-out rights, ArmourID does not currently offer a separate automated decision-making opt-out. If our practices change and we use automated decision-making technology in a way that is subject to these rights, we will update this Notice and provide any required notices, explanations, and rights as required by applicable law.
9. Biometric and Identity Verification Information
Some features of the Services use identity verification tools that involve government identification documents, photographs, liveness checks, facial comparison, or similar verification processes. These features may be provided by ArmourID or by a third-party identity verification provider.
- Transparency and Consent. Before collecting or obtaining biometric identifiers or biometric information, ArmourID will: (1) inform you in writing that biometric data is being collected or stored; (2) inform you in writing of the specific purpose and length of time for which the biometric data is being collected, stored, and used; and (3) obtain your written release, which may include an electronic signature or other legally valid electronic consent.
- Retention and Destruction — Illinois BIPA. See Exhibit A (Biometric Data Retention and Destruction Policy) for the complete publicly available retention schedule and destruction guidelines required by Illinois BIPA §15(a). In summary: biometric identifiers and biometric information are destroyed no later than the earlier of (1) three years from your last interaction with ArmourID, or (2) when the initial purpose for collection has been satisfied.
- No Profit from Biometric Data. ArmourID will not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. Biometric data will not be disclosed except as described in this Notice, as authorized by you, or as required by law.
- Third-Party Verification Providers. If a third-party identity verification provider collects or processes biometric information on our behalf, that provider is required to protect the information in accordance with applicable law and this Notice, and is prohibited from using it for any purpose other than providing identity verification services to ArmourID.
10. Cookies and Tracking Technologies
We use cookies, pixels, logs, software development kits, APIs, and similar technologies to operate, secure, maintain, and improve the Services; remember your preferences; understand how users interact with the Services; troubleshoot technical issues; support integrations; detect and prevent fraud or misuse; and measure performance.
These technologies may collect information such as IP address, device type, browser type, operating system, device identifiers, pages or screens viewed, referring URLs, access dates and times, interactions with features or content, error logs, and other usage or technical information. We may use the following types of cookies and similar technologies:
- Essential and Security Technologies. These technologies are necessary to operate the Services, authenticate users, maintain account security, prevent fraud, remember privacy choices, enable core platform functionality, and support legal or compliance requirements. These technologies cannot generally be disabled through our preference tools.
- Preference and Functionality Technologies. These technologies help us remember your settings and preferences, such as login status, language, saved choices, or other platform settings.
- Analytics and Performance Technologies. These technologies help us understand how the Services are used, identify performance issues, improve functionality, and support internal analytics and reporting. For example, we may use analytics tools to understand page views, navigation paths, feature usage, technical errors, and general usage trends.
- Integration and Service Technologies. Some features of the Services may rely on third-party tools, APIs, or integrations, such as identity verification, communications, payment processing, scheduling, document management, storage, security, analytics, or other service-related functionality. These third parties may collect or receive information as needed to provide their services to ArmourID or to you.
- Session Replay and Similar Technologies. We may use session replay or similar analytics tools to understand how users interact with the Services, diagnose technical issues, improve usability, and maintain platform functionality. These tools may record interactions such as clicks, taps, scrolling, navigation paths, page performance, and error events. Where we use these tools, we implement reasonable measures designed to prevent the capture of passwords, payment details, and other sensitive information entered into forms. ArmourID does not knowingly use session replay or analytics tools to capture medical documents, government identification documents, biometric information, payment card information, passwords, or other sensitive form-field content.
Where required by applicable law, ArmourID will obtain consent before using non-essential cookies, analytics, session replay, SDKs, or similar technologies.
11. Third Party Integrations
The Services may contain links to, integrate with, or allow you to interact with third-party websites, applications, platforms, tools, APIs, or services that ArmourID does not own or control. These may include, for example, identity verification providers, payment processors, communications providers, analytics tools, document or storage providers, scheduling tools, regulatory or commission systems, or other operational integrations.
When you use a third-party service or integration, that third party may collect, receive, or process personal information in accordance with its own privacy notice, terms, and practices. ArmourID is not responsible for the privacy, security, or data practices of third-party services that are not acting on ArmourID’s behalf. We encourage you to review the applicable third party’s privacy notice before using those services.
Where a third-party provider processes personal information on ArmourID’s behalf, we use reasonable measures designed to limit that provider’s use of personal information to providing services to ArmourID or as otherwise permitted by law.
12. Your Privacy Rights
Depending on your state of residence, you may have some or all of the rights listed below. Rights vary by state.
Rights That May Not Apply Based on Our Current Practices. Some privacy laws provide additional rights in specific circumstances, such as the right to opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, certain profiling, or certain automated decision-making activities. Based on ArmourID’s current practices:
- ArmourID does not sell personal information.
- ArmourID does not share personal information for cross-context behavioral advertising.
- ArmourID does not process personal information for targeted advertising.
- ArmourID does not use automated decision-making technology to make decisions that produce legal or similarly significant effects.
- ArmourID uses and discloses sensitive personal information only for purposes permitted by law, such as providing the Services, identity verification, eligibility and regulatory workflows, fraud prevention, security, legal compliance, customer support, and ordinary business operations.
Because ArmourID does not currently engage in these activities, we do not currently offer separate opt-out rights for sale, sharing, targeted advertising, qualifying profiling, automated decision-making, or a separate “Limit the Use of My Sensitive Personal Information” link. If our practices change and we engage in activities that trigger these rights, we will update this Notice and provide any required privacy choices.
How We Verify Privacy Requests.
We will verify your identity before processing your request, where required or permitted by law. Verification may include matching information you provide against information we maintain, requesting additional information, or requiring you to confirm access to the email address associated with your account. We will use information provided for verification only to verify and process your request.
How We Respond to Privacy Requests.
We will respond to privacy rights requests within the time required by applicable law. If we deny your request in whole or in part, we will explain the reason for the denial where required. Where applicable, you may appeal our decision by contacting us at the email listed in Section 20 (Contact Us) with the subject line “Privacy Appeal.”
Authorized Agents.
Where permitted by law, you may designate an authorized agent to submit a privacy request on your behalf. We may require proof that you authorized the agent to act for you, and we may also require you to verify your identity directly with us.
13. Data Retention
We retain personal information for as long as needed to provide the Services, support regulatory workflows, comply with legal obligations, resolve disputes, and maintain security. When information is no longer needed, we delete, deidentify, or aggregate it in accordance with applicable law.
Retention periods may vary by data type, user role, applicable athletic commission or sanctioning body requirements, legal or contractual recordkeeping obligations, active disputes, safety or eligibility needs, and the status of your account or authorization. Biometric information is retained and destroyed as described in Exhibit A (Biometric Data Retention and Destruction Policy).
14. Security
ArmourID uses reasonable technical, administrative, and organizational safeguards designed to protect your personal information against unauthorized access, disclosure, alteration, or loss. These safeguards include encryption of data in transit and at rest, access controls, authentication requirements, and security monitoring.
No system is completely secure. If we become aware of a security incident involving personal information, we will investigate, contain, and remediate the incident and provide notifications as required by applicable law.
15. SMS, Email, and Communications Consent
ArmourID may send you service-related communications, including account alerts, document expiration notices, eligibility status updates, and platform notifications, by email, SMS, or in-platform notification.
SMS Text Messages.
By providing your mobile phone number and opting in to SMS notifications through the platform, you consent to receive text messages from ArmourID related to your account and the Services. Message frequency varies based on your account activity and notification settings. Message and data rates may apply.
- Transactional and service-related SMS messages: If you provide your mobile phone number and enable SMS notifications, you consent to receive service-related text messages related to your account and the Services. Consent to receive SMS messages is not a condition of purchase or use of the Services unless SMS is required for a specific security or authentication feature.
- Marketing or promotional SMS messages, if any: require your separate prior express written consent, which we will obtain at the time of opt-in.
To stop receiving SMS messages, reply STOP to any ArmourID text message or update your notification settings in the platform. For help, reply HELP or contact info@armour-id.com.
Email Communications.
We send transactional emails (account confirmations, document alerts, security notices) as part of the Services. You may manage email preferences through your account settings. Opting out of marketing emails will not affect your receipt of service-critical transactional communications.
16. HIPAA — What Applies and What Doesn’t
ArmourID is not a healthcare provider, health plan, or healthcare clearinghouse. In most use cases involving fighters, athletes, promotions, gyms, athletic commissions, and sanctioning bodies, ArmourID is not acting as a HIPAA covered entity or business associate simply by providing the Services. However, this determination depends on the specific nature of each relationship. If ArmourID is engaged by an entity that is itself a HIPAA covered entity, and ArmourID receives or handles protected health information (PHI) on that entity’s behalf, a Business Associate Agreement (BAA) may be required. In those circumstances, that specific processing will be governed by the applicable BAA and HIPAA requirements.
17. Minor Athletes — Children’s Privacy
The Services are intended for users who are 18 years of age or older. Individuals under 18 may not create an account or use the Services directly unless expressly permitted by ArmourID and supported by any required parent, guardian, organizational, or regulatory authorization.
ArmourID does not knowingly collect personal information online directly from children under 13 without verifiable parental consent where required by the Children’s Online Privacy Protection Act (“COPPA”). If we learn that we have collected personal information online directly from a child under 13 without required consent, we will take reasonable steps to delete the information or obtain appropriate consent, as required by law.
In some cases, personal information about minor athletes may be submitted to the Services by a parent or guardian, athletic commission, promotion, gym, sanctioning body, organization, or other authorized representative. This information may include profile information, eligibility information, identity information, participation records, consent documentation, medical or health-related documentation, and other information needed to support eligibility, licensing, medical clearance, compliance, event participation, or regulatory workflows.
ArmourID uses minor athlete information only for the purposes described in this Notice, including to provide and operate the Services, support eligibility and regulatory workflows, maintain documentation, verify identity or authorization, communicate with authorized parties, prevent fraud, maintain security, and comply with legal, contractual, or regulatory obligations.
ArmourID does not sell personal information of minors, share personal information of minors for cross-context behavioral advertising, or process minor personal information for targeted advertising.
Parents or guardians may contact us to request access to, correction of, or deletion of personal information about their minor child, or to request that ArmourID stop future use or disclosure of that information, subject to applicable legal, regulatory, contractual, documentation, safety, eligibility, and recordkeeping exceptions. To submit a request, contact us at info@armour-id.com. We may need to verify your identity and authority to act on behalf of the minor before processing the request.
Where an organization, commission, promotion, gym, sanctioning body, or other representative submits minor athlete information to the Services, that organization or representative is responsible for obtaining any required parent, guardian, athlete, regulatory, or other authorization before submitting the information to ArmourID.
ArmourID may require the submitting organization or representative to provide evidence of the required consent, authorization, or legal authority before enabling access to, use of, or disclosure of minor athlete information.
ArmourID may restrict or suspend access to minor athlete features if we determine that required authorizations, notices, or approvals have not been obtained.
18. U.S.-Based Services and International Users
ArmourID is based in the United States, and the Services are designed for use in the United States. If you access the Services from outside the United States, your information may be processed and stored in the United States, where privacy laws may differ from those in your home jurisdiction. By using the Services from outside the United States, you acknowledge that your information will be transferred to and processed in the United States. International users who have questions about data transfers should contact info@armour-id.com.
19. Changes to This Notice
We may update this Privacy Notice from time to time. The effective date at the top of the document will reflect any changes. If we make material changes — including changes to how we process sensitive personal information, consumer health data, or biometric data — we will provide notice through the platform, by email, or by other reasonable means before the changes take effect, and will obtain new consent where required by law.
20. Contact Us
Questions, requests, or concerns regarding this Privacy Notice should be directed to:
Part II — Consumer Health Data Privacy Notice
Definition
“Consumer health data” means personal information linked or reasonably linkable to a consumer that identifies, or could reasonably be used to identify, the consumer’s past, present, or future physical or mental health status.
Consumer Health Data ArmourID May Collect
For ArmourID, consumer health data may include medical and health-related information used to support eligibility, medical clearance, documentation, participation, compliance, or regulatory workflows, including:
- Medical examination records, physicals, and medical clearances
- Bloodwork or lab results
- Vaccination or immunization records
- Imaging records and physician letters
- Injury records and suspension-related medical records
- Medical expiration dates and documentation status information
- Biometric or liveness information, to the extent used in connection with health-related eligibility, identity verification, or regulatory workflows
Required Disclosures Summary
The list below summarizes disclosures required by applicable consumer health data privacy law. Cross-references point to the corresponding section of the ArmourID Privacy Notice (Part I) for additional detail.
- Categories of consumer health data collected: see this Part II (Consumer Health Data ArmourID May Collect) and Part I, Section 2 (Personal Information We Collect).
- Sources of consumer health data: see Part I, Section 3 (How Personal Information is Collected).
- Purposes for which consumer health data is used: see Part I, Section 5 (How Personal Information is Used).
- Categories of third parties with whom consumer health data may be shared: see Part I, Section 6 (Disclosures of Personal Information).
- Your rights regarding consumer health data and how to exercise them: see Part I, Section 12 (Your Privacy Rights) and How to Submit a Consumer Health Data Request below.
- How ArmourID protects consumer health data: see Part I, Section 14 (Security).
Restrictions on Use
ArmourID does not sell consumer health data, share consumer health data with data brokers, or use consumer health data for targeted advertising, advertising profiles, or cross-context behavioral advertising. ArmourID uses consumer health data only for the limited purposes described in Part I of this Notice and as otherwise permitted by applicable law.
How to Submit a Consumer Health Data Request
Depending on where you live and subject to applicable legal exceptions, you may have the right to confirm whether ArmourID collects, shares, or sells consumer health data about you; access your consumer health data; receive information about the third parties or affiliates with whom ArmourID has shared or sold your consumer health data; withdraw consent for future collection or sharing of consumer health data; request correction of inaccurate consumer health data, where required by applicable law; request deletion of consumer health data subject to exceptions; and appeal a denied request. ArmourID does not sell consumer health data, share consumer health data with data brokers, or use consumer health data for targeted advertising or advertising profiles, so ArmourID does not offer a separate opt-out right for those activities.
To submit such a request, contact ArmourID using the process described in Section 12 (Your Privacy Rights) of the ArmourID Privacy Notice, and include “Consumer Health Data Request” in the subject line. We may verify your identity and authority before processing your request.
Updates to This Policy
We may update this Part II from time to time. If we materially change how we collect, use, or disclose consumer health data, we will provide notice and obtain consent where required by applicable law.
Exhibit A — Biometric Data Retention and Destruction Policy
Effective Date: May 29, 2026
ArmourID maintains this Biometric Data Retention and Destruction Policy under the Illinois Biometric Information Privacy Act, 740 ILCS 14/15(a).
ArmourID may collect or possess biometric identifiers or biometric information, including face geometry data, in connection with identity verification.
ArmourID retains biometric identifiers and biometric information only for as long as needed to complete the purpose for which they were collected. ArmourID will permanently destroy biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within three years of the individual’s last interaction with ArmourID, whichever occurs first, unless retention is required by a valid warrant, subpoena, or other legal obligation.
Permanent destruction means deletion or destruction in a manner designed to make the biometric identifiers or biometric information no longer retrievable or usable by ArmourID.
ArmourID will apply this policy to biometric identifiers and biometric information in ArmourID’s possession, whether collected directly by ArmourID or collected by a third-party identity verification provider on ArmourID’s behalf.
Questions about this policy may be directed to: info@armour-id.com.
ARMOURID LLC
Digital Identity & Medical Eligibility Platform for Combat Sports
www.armour-id.com | info@armour-id.com | Effective Date: May 29, 2026