Skip to content
Saturday, August 29, 2026 · Global Edition
NUV Media
PAYMENTS · FINTECH · BANKING
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
Home / Innovation

How Palm and Face Payments Verify You at Biometric Checkout

Biometric checkout systems match a stored mathematical template of a palm or face to a linked payment token, and state statutes such as Illinois BIPA now define what operators may do with that template afterward.

Close-up of a palm hovering over a glowing biometric payment scanner
Palm-vein matching converts one scan into a template that releases a tokenized card authorization.

Amazon One, the palm-reading payment service Amazon launched in 2020, operates at hundreds of U.S. locations including Whole Foods Market stores, Amazon's own retail formats and sports venues (Amazon, 2024). Mastercard opened its Biometric Checkout Program to pilots in April 2022, beginning with Brazilian merchants (Mastercard, 2022). Both turn a body measurement into a payment credential.

Nuv Media publishes information, not financial advice. This explainer covers how palm and face checkout works technically, where named deployments stood as of March 2026, and what privacy rules apply in the states that regulate biometric data most tightly.

How does a palm or face become a payment credential?

Enrollment converts a scan into a template, and the template becomes the key that releases a payment token. A camera or palm sensor captures the image, software extracts distinguishing measurements — surface ridges and vein patterns for a palm, geometric distances for a face — and stores the result as a mathematical representation. The raw image is not the credential; the template derived from it is.

At checkout the flow runs in reverse. The sensor captures a fresh scan, the matching engine compares it against enrolled templates, and a match returns a customer record holding a card-on-file or network token. The merchant then processes an ordinary tokenized card authorization — the biometric never touches the payment network itself. If no match clears, the terminal falls back to a card tap, so stores treat biometric checkout as an alternative front end to standard acquiring.

Two architectures sit behind that flow. In merchant-side systems like Amazon One, matching happens against templates held in a central service — Amazon says palm signatures are encrypted and stored in its AWS cloud, not on the scanning device (Amazon, 2024). In phone-based checkout, the same Face ID or fingerprint match runs inside the handset's secure hardware and releases a wallet token; the template never leaves the device. Payments professionals treat these as different risk models, not variations of one product.

Where are these systems actually deployed?

Named U.S. deployments remain concentrated in retail chains with a single operator. Amazon One launched in Seattle in 2020, expanded across Whole Foods Market stores starting in 2023, and added age verification for alcohol purchases at venues such as Coors Field (Amazon, 2023). Panera Bread piloted Amazon One at St. Louis bakery-cafes in 2022 (Panera Bread, 2022). Outside the U.S., Mastercard's program ran face and palm pilots with Fujitsu technology at Brazilian merchants including a Sao Paulo supermarket run with Itau cardholders (Mastercard, 2022).

The rollout pattern matters for analysts: adoption is deepest where one company controls the store, the scanner and the loyalty program. General merchant acceptance — where an acquirer would have to support several competing biometric schemes — has moved slowly, and no U.S. card network had opened biometric checkout to general merchant acceptance as of March 2026. Mastercard's program, announced as a path to that goal, remained in pilot markets rather than a live U.S. network service (Mastercard, 2022).

What happens to biometric data after enrollment?

Templates are the asset and the liability. A palm vein template or faceprint cannot be reissued the way a card number can; if the database leaks, the exposed measurements are permanently connected to one person. That is why storage location — cloud vault versus on-device secure element — is the first question security teams ask about any biometric checkout deployment.

Operators publish different answers. Amazon says palm images are converted into a palm signature, encrypted, and stored in the AWS Cloud, with deletion available by phone hotline and a two-step process that also requires presenting an ID (Amazon, 2024). Mastercard's program materials describe biometric templates held by the technology provider under payment-card-grade controls, with the card credential tokenized separately (Mastercard, 2022). Phone-based face matching keeps the template in the device's secure enclave and shares nothing with the merchant.

Secondary use is the second question. Amazon One doubles as an age-verification and loyalty-identification tool, which means one palm enrollment serves several business functions — exactly the kind of scope creep that privacy statutes were written to police.

What do regulators require for biometric payments?

Illinois sets the strictest rule. Its Biometric Information Privacy Act, in force since 2008, requires written consent and a public retention-and-destruction schedule before collecting biometric identifiers, and grants a private right of action with statutory damages of 1,000 dollars per negligent violation and 5,000 dollars for intentional or reckless ones (740 ILCS 14). In February 2023 the Illinois Supreme Court held in Cothron v. White Castle that claims accrue with every scan, not just the first collection — exposure that shapes every deployment decision in the state.

Enforcement elsewhere is accelerating. The Texas attorney general settled with Meta for 1.4 billion dollars in July 2024 under the state's Capture or Use of Biometric Identifier Act, a statute only the attorney general may enforce (Texas Attorney General, 2024). New York City's Local Law 117 of 2021 requires retailers that collect biometric identifiers to post conspicuous signs. The Federal Trade Commission warned in a September 2023 policy statement that mishandling biometric data or overstating its accuracy can violate Section 5 of the FTC Act (FTC, 2023), and California treats biometric information as sensitive personal data under the CCPA as amended by the CPRA (California Attorney General, 2023).

For a payments team, the compliance checklist follows from those statutes: informed written consent at enrollment, published retention and deletion timelines, encryption in transit and at rest, an audited deletion path, and signage where local law demands it. Deployments that skip any one of these tend to surface first as class-action dockets, not as security incidents.

Jacob Hoffman

Independent editorial contributor focused on AI, cybersecurity, digital privacy, technology explainers.

Jacob Hoffman approaches crypto and AI with curiosity, but starts with the question most people skip: what could go wrong?

More about Jacob Hoffman

Frequently Asked Questions

Does biometric checkout send my face or palm to the payment network?
No. The biometric match happens between the terminal and the operator's template database; a successful match simply triggers a standard tokenized card authorization from a stored payment credential. Card networks never receive the face or palm data. In phone-based checkout the template stays on the device and only releases the wallet token.
How is Amazon One palm data stored?
Amazon says palm images are converted into an encrypted palm signature and stored in its AWS cloud, not on the scanning device. Customers can request deletion through a phone hotline and a two-step identity process. Enrollment links that signature to a payment card and phone number, which is how one palm works across Whole Foods and Amazon stores.
Which states regulate biometric payments most strictly?
Illinois leads. Its 2008 Biometric Information Privacy Act requires written consent and a public destruction schedule, with a private right of action of 1,000 to 5,000 dollars per violation. Texas lets only its attorney general sue and won a 1.4-billion-dollar settlement from Meta in 2024. New York City requires posted signs, and California classifies biometrics as sensitive personal information.
Can biometric checkout payments be disputed like card payments?
Yes, because the payment leg is an ordinary card authorization against a tokenized credential. Chargebacks and network dispute rules apply as they would to any card-on-file transaction. The biometric layer affects fraud liability arguments — proof that a template matched — but it does not create a separate dispute rail.

Sources

  1. Amazon One launch 2020, deployment at hundreds of U.S. locations including Whole Foods, palm signature encrypted and stored in AWS cloud, deletion process, age verification at Coors FieldAmazon (Amazon One announcements and FAQ)
  2. Mastercard Biometric Checkout Program announced April 2022 with pilots in Brazil using Fujitsu technologyMastercard press release, Biometric Checkout Program
  3. Illinois BIPA consent, retention schedule and statutory damages of 1,000 and 5,000 dollars; Cothron v. White Castle per-scan accrual, February 2023Illinois Biometric Information Privacy Act (740 ILCS 14); Illinois Supreme Court
  4. Texas Capture or Use of Biometric Identifier Act enforcement and 1.4-billion-dollar Meta settlement, July 2024Texas Attorney General
  5. FTC Policy Statement on Biometric Information and Section 5 of the FTC Act, September 2023Federal Trade Commission
  6. Biometric information treated as sensitive personal information under CCPA as amended by CPRACalifornia Attorney General, CCPA regulations