Amazon One, the palm-reading payment service Amazon launched in 2020, operates at hundreds of U.S. locations including Whole Foods Market stores, Amazon's own retail formats and sports venues (Amazon, 2024). Mastercard opened its Biometric Checkout Program to pilots in April 2022, beginning with Brazilian merchants (Mastercard, 2022). Both turn a body measurement into a payment credential.
Nuv Media publishes information, not financial advice. This explainer covers how palm and face checkout works technically, where named deployments stood as of March 2026, and what privacy rules apply in the states that regulate biometric data most tightly.
How does a palm or face become a payment credential?
Enrollment converts a scan into a template, and the template becomes the key that releases a payment token. A camera or palm sensor captures the image, software extracts distinguishing measurements — surface ridges and vein patterns for a palm, geometric distances for a face — and stores the result as a mathematical representation. The raw image is not the credential; the template derived from it is.
At checkout the flow runs in reverse. The sensor captures a fresh scan, the matching engine compares it against enrolled templates, and a match returns a customer record holding a card-on-file or network token. The merchant then processes an ordinary tokenized card authorization — the biometric never touches the payment network itself. If no match clears, the terminal falls back to a card tap, so stores treat biometric checkout as an alternative front end to standard acquiring.
Two architectures sit behind that flow. In merchant-side systems like Amazon One, matching happens against templates held in a central service — Amazon says palm signatures are encrypted and stored in its AWS cloud, not on the scanning device (Amazon, 2024). In phone-based checkout, the same Face ID or fingerprint match runs inside the handset's secure hardware and releases a wallet token; the template never leaves the device. Payments professionals treat these as different risk models, not variations of one product.
Where are these systems actually deployed?
Named U.S. deployments remain concentrated in retail chains with a single operator. Amazon One launched in Seattle in 2020, expanded across Whole Foods Market stores starting in 2023, and added age verification for alcohol purchases at venues such as Coors Field (Amazon, 2023). Panera Bread piloted Amazon One at St. Louis bakery-cafes in 2022 (Panera Bread, 2022). Outside the U.S., Mastercard's program ran face and palm pilots with Fujitsu technology at Brazilian merchants including a Sao Paulo supermarket run with Itau cardholders (Mastercard, 2022).
The rollout pattern matters for analysts: adoption is deepest where one company controls the store, the scanner and the loyalty program. General merchant acceptance — where an acquirer would have to support several competing biometric schemes — has moved slowly, and no U.S. card network had opened biometric checkout to general merchant acceptance as of March 2026. Mastercard's program, announced as a path to that goal, remained in pilot markets rather than a live U.S. network service (Mastercard, 2022).
What happens to biometric data after enrollment?
Templates are the asset and the liability. A palm vein template or faceprint cannot be reissued the way a card number can; if the database leaks, the exposed measurements are permanently connected to one person. That is why storage location — cloud vault versus on-device secure element — is the first question security teams ask about any biometric checkout deployment.
Operators publish different answers. Amazon says palm images are converted into a palm signature, encrypted, and stored in the AWS Cloud, with deletion available by phone hotline and a two-step process that also requires presenting an ID (Amazon, 2024). Mastercard's program materials describe biometric templates held by the technology provider under payment-card-grade controls, with the card credential tokenized separately (Mastercard, 2022). Phone-based face matching keeps the template in the device's secure enclave and shares nothing with the merchant.
Secondary use is the second question. Amazon One doubles as an age-verification and loyalty-identification tool, which means one palm enrollment serves several business functions — exactly the kind of scope creep that privacy statutes were written to police.
What do regulators require for biometric payments?
Illinois sets the strictest rule. Its Biometric Information Privacy Act, in force since 2008, requires written consent and a public retention-and-destruction schedule before collecting biometric identifiers, and grants a private right of action with statutory damages of 1,000 dollars per negligent violation and 5,000 dollars for intentional or reckless ones (740 ILCS 14). In February 2023 the Illinois Supreme Court held in Cothron v. White Castle that claims accrue with every scan, not just the first collection — exposure that shapes every deployment decision in the state.
Enforcement elsewhere is accelerating. The Texas attorney general settled with Meta for 1.4 billion dollars in July 2024 under the state's Capture or Use of Biometric Identifier Act, a statute only the attorney general may enforce (Texas Attorney General, 2024). New York City's Local Law 117 of 2021 requires retailers that collect biometric identifiers to post conspicuous signs. The Federal Trade Commission warned in a September 2023 policy statement that mishandling biometric data or overstating its accuracy can violate Section 5 of the FTC Act (FTC, 2023), and California treats biometric information as sensitive personal data under the CCPA as amended by the CPRA (California Attorney General, 2023).
For a payments team, the compliance checklist follows from those statutes: informed written consent at enrollment, published retention and deletion timelines, encryption in transit and at rest, an audited deletion path, and signage where local law demands it. Deployments that skip any one of these tend to surface first as class-action dockets, not as security incidents.
For more context, read How Agentic Commerce Would Let AI Agents Pay for You.
For more context, read wallet provisioning.
For more context, read ai underwriting banks.




