| |

Home Depot Is Using Facial Recognition for Some Rentals. Can You Say No?

You walk into Home Depot to rent a pressure washer. You have your driver’s license. You have a credit card. You are standing in front of an actual employee who can look at you and compare your face with the photograph on your government-issued ID.

And then you’re asked to submit to facial identity verification.

It sounds like something you might expect while going through airport security or accessing a highly secure building. But facial-recognition and biometric identity technology is increasingly moving into much more ordinary transactions—including renting tools and vehicles.

Home Depot confirms in its own privacy disclosures that it collects facial-recognition information and may require customers to undergo “enhanced identity verification” involving facial images and identification documents.

So before you scan your face to rent that pressure washer, there are some things worth understanding.

Yes, Home Depot says it uses facial recognition

This isn’t merely anecdotal.

In its current Privacy & Security Statement, Home Depot lists “facial recognition” under the category of biometric information it collects. The company says the information may be collected through cameras at select stores, parking lots and other facilities and used for fraud prevention, security and asset protection.

Elsewhere in the same privacy statement, Home Depot specifically identifies “confirming the identity of our customers who rent trucks or certain types of tools or equipment” as one of its security and asset-protection activities.

And there is an even more explicit disclosure.

Under a section titled “For enhanced identity verification,” Home Depot says that in certain circumstances it may require customers to participate in enhanced verification with Home Depot or one of its third-party partners. According to the company, those processes may include processing facial images or identification documents.

In other words, the request to provide a facial image before renting equipment is not simply an overzealous employee inventing a new rule.

It is part of a broader identity-verification system Home Depot acknowledges using.

Some renters are being directed through CLEAR

Numerous customers and Home Depot employees have reported that some rental transactions use CLEAR, the identity-verification company best known to travelers for its airport identity services.

Customers have described scanning a QR code, providing identifying information, photographing a driver’s license and taking a selfie before being permitted to proceed with a rental.

CLEAR itself describes essentially this type of technology on its identity-verification website. In a typical selfie-verification transaction, a user takes a selfie and provides a government-issued ID. The system checks whether the person is physically present and compares the face in the selfie with the photograph on the ID, along with additional identity and security signals.

CLEAR says that it handles the biometric portion of identity verification so that its business customers don’t have to, and that information is shared with a customer according to what the user has consented to share.

Home Depot’s public privacy statement, however, does not identify CLEAR by name as its tool-rental verification provider. So consumers should pay attention to the company identified on the verification screen they encounter rather than assume every Home Depot rental uses the same provider.

Why isn’t a driver’s license enough anymore?

From Home Depot’s perspective, there is an understandable problem to solve.

Tools, trucks and other expensive equipment can be stolen, rented using fraudulent identification or simply never returned. A person carrying a driver’s license isn’t necessarily the person whose photograph appears on it.

Automated identity verification provides another layer of protection by asking software to determine whether the person presenting the ID is actually the person pictured on it.

That can reduce identity fraud.

But it also raises a perfectly reasonable consumer question:

How much personal information should someone have to surrender to rent a piece of equipment?

For generations, a clerk could inspect a government-issued photo ID. Increasingly, businesses are outsourcing that judgment to automated identity systems capable of analyzing a person’s face.

And your face isn’t quite like a password.

If a password is compromised, you can change it.

You cannot change your face.

What actually happens when a computer “looks” at your face?

Facial verification generally doesn’t work the same way a human being looks at two photographs and decides they resemble each other.

Modern systems analyze characteristics of facial images mathematically and calculate whether two images are sufficiently similar to conclude that they depict the same person.

CLEAR describes its current system as going considerably beyond a simple photograph comparison. Its CLEAR1 identity-verification platform uses a selfie along with other signals to establish that a real person is present, authenticate identity information and detect potential fraud.

That distinction matters because there is a difference between a store employee merely looking at your driver’s license and a technology company processing your facial characteristics.

What happens to the information afterward?

That’s one of the most important questions consumers should ask.

Home Depot’s privacy statement says biometric information may be disclosed to service providers processing information on its behalf, including security and fraud-prevention providers. It also says information may be disclosed to law enforcement or government authorities when Home Depot considers disclosure reasonably necessary to comply with the law, assist investigations or protect people or property.

The company classifies biometric information among the information that “may be considered sensitive personal information.”

Home Depot does not promise in its general privacy statement that all facial-recognition information is immediately destroyed after a transaction. Instead, the company says it keeps personal information for as long as “reasonably necessary” for the purpose for which it was collected, with retention potentially affected by recordkeeping requirements, fraud prevention, legal claims, security and other considerations.

If CLEAR performs the verification, its own privacy policy is also relevant. CLEAR says it retains personal information as necessary to provide its services, meet the purposes described in its policy and satisfy legal, fraud-prevention and contractual requirements.

Importantly, CLEAR also says it allows users to request access to their personal information, request deletion, withdraw consent in applicable circumstances and exercise other privacy rights. Some information may nevertheless be retained for legal or fraud-prevention purposes.

Facial recognition isn’t infallible

facial recognition.
Image credit metamorworks via Shutterstock.

There is another reason consumers may be uncomfortable making automated facial verification a gateway to everyday goods and services: the technology can make mistakes.

The National Institute of Standards and Technology, which conducts extensive testing of facial-recognition algorithms, has documented differences in error rates associated with age, sex and race, although performance varies substantially among algorithms and modern systems have improved considerably.

NIST distinguishes between false positives—incorrectly determining that two different people are the same person—and false negatives, in which a system fails to recognize two images of the same person.

For a rental customer, a false negative could mean something relatively mundane but infuriating: You are you, your driver’s license is yours, but the computer won’t approve you.

Image quality can also matter. Lighting, camera angle and other photographic conditions can affect facial-verification performance.

The federal government has concerns about biometric technology, too

The privacy questions surrounding this technology aren’t hypothetical.

The Federal Trade Commission issued a formal warning about biometric technologies, saying their increasing use creates potential privacy, security, bias and discrimination risks.

Among the practices the FTC said it would consider when evaluating whether a company’s use of biometric technology is unfair are failing to assess foreseeable harms, failing to take reasonable precautions against those harms and engaging in unexpected or undisclosed collection or use of biometric information.

That doesn’t mean facial verification itself is illegal. It means companies deploying it still have obligations concerning how they represent, secure and use the technology.

What about Florida?

The experience that prompted this article occurred at a Home Depot in Florida, which makes the state’s privacy law particularly interesting.

Florida’s Digital Bill of Rights explicitly gives covered consumers a right to opt out of the collection of personal data through a facial-recognition or voice-recognition feature.

That sounds straightforward—but there’s an enormous qualification.

Florida’s law applies its principal “controller” definition to an unusually narrow category of companies. Under Florida Statute 501.702, a covered controller generally must have more than $1 billion in annual global revenue and meet additional criteria involving businesses such as online advertising, smart speakers and virtual assistants, or large app stores and digital distribution platforms.

That means Florida’s facial-recognition opt-out provision should not be interpreted as a blanket right allowing every Florida consumer to refuse every company’s facial-verification system.

There’s another legal wrinkle. Florida’s statutory definition of “biometric data” specifically excludes photographs, video and audio recordings—and data generated from those recordings—even though the law separately addresses information collected through facial-recognition features.

Privacy law in this area is anything but simple.

Want to know what your state says about facial recognition?

Privacy protections vary dramatically depending on where you live.

The National Conference of State Legislatures’ Consumer Privacy Legislation Database allows consumers to select their state and search specifically for laws and proposed legislation involving biometrics or facial recognition.

The International Association of Privacy Professionals’ U.S. State Privacy Legislation Tracker also provides a state-by-state map of comprehensive consumer privacy laws and the rights they provide.

One caution: having a state privacy law does not automatically mean you have the right to refuse facial verification in every situation. Some laws apply only to certain companies, certain types of data or particular uses of that data. Biometric-specific laws can also provide protections that aren’t contained in a state’s general consumer privacy law.

Can you simply refuse?

Possibly—but refusing may also mean the company declines the rental.

Home Depot’s public privacy statement says enhanced identity verification may be required in certain circumstances. It does not clearly establish a nationwide right for a customer to demand ordinary manual driver’s-license verification instead.

If you’re uncomfortable, ask before providing anything:

Is facial verification required for this particular rental?

Is there a manual ID-verification alternative?

Which company is processing my facial image?

Is a biometric identifier or template being created?

How long will my selfie, ID image or biometric information be retained?

Can I have that information deleted after the rental is complete?

If the answer is that facial verification is mandatory and you don’t want to participate, your practical option may be to rent from another company.

You can ask companies what they have about you

Even when a particular state privacy statute doesn’t provide all the rights a consumer might expect, it’s worth checking the company’s own privacy program.

Home Depot maintains a Privacy & Security Center explaining its data practices and consumer privacy options.

CLEAR goes further in its published policy. It says it honors privacy rights for its members regardless of where they live, although particular rights remain subject to legal exceptions and limitations. Consumers can request access to their data and request deletion through CLEAR’s privacy process.

If you underwent facial verification and are concerned about what was retained, asking both the retailer and the identity-verification provider is reasonable.

The bigger question isn’t really about a pressure washer

There is a legitimate reason for a rental company to verify the identity of someone walking away with hundreds or thousands of dollars’ worth of equipment.

But there is also a legitimate debate about proportionality.

We’ve gradually become accustomed to providing increasingly intimate forms of identification in exchange for ordinary services. Face ID unlocks phones. Airports use facial comparison. Banks request selfies to open accounts. Employers use automated identity systems. And now someone renting equipment at a home-improvement store may encounter similar technology.

Each individual use can sound reasonable.

Taken together, however, they represent a significant change in everyday life: your physical identity is increasingly becoming a credential.

That deserves more scrutiny than clicking “agree” because there’s a line behind you at the rental counter.

Before handing over biometric or facial information, consumers have every reason to ask three very simple questions:

What are you collecting? Who gets it? And when will you delete it?

Those aren’t paranoid questions.

They’re becoming basic digital hygiene.

You may want to read:

Author

  • Robin Jaffin headshot circle

    Robin Jaffin is a strategic communicator and entrepreneur dedicated to impactful storytelling, environmental advocacy, and women's empowerment. As Co-Founder of The Queen Zone™, Robin amplifies women's diverse experiences through engaging multimedia content across global platforms. Additionally, Robin co-founded FODMAP Everyday®, an internationally recognized resource improving lives through evidence-based health and wellness support for those managing IBS. With nearly two decades at Verité, Robin led groundbreaking initiatives promoting human rights in global supply chains.

    View all posts

Similar Posts