Going to production
Apply once, then move from sandbox faces on one phone to real faces, enrolled with consent and synced to every device.
Your verify code stays the same. What changes is where faces come from: in production they're enrolled with the person's consent and synced to the devices that need them.
1. Apply to go live#
From app.faceping.ai, choose Apply to go live and tell us what you're building. We check the use case once (face templates are biometric data under GDPR and several US state laws), usually within two working days. Keep building in the sandbox while you wait.
2. Choose how faces are grouped#
| Use | Create a… | Faces are deleted |
|---|---|---|
| Events and ticketing | Event, with a start and end | Automatically, up to 30 days after the event |
| Memberships, staff, kiosks | Group, with no end date | When you remove the member, or after the inactivity period you set |
Both work the same way on the device.
3. Enrol people, with consent#
Pick whichever suits where people already are:
- The FacePing widget on your sign-up or ticket page: we show the consent wording, take the selfie and enrol them. See The enrolment widget.
- Your own server, if you collect the photo and consent yourself: see Server-side enrolment.
- The dashboard, at a staffed desk or reception.
4. Pair each device#
Create a device token for the group or event (Dashboard → Gate devices, or the API), and give it to the app instead of the sandbox key:
builder.UseFacePing(o => o.DeviceToken = deviceToken);
The device downloads an encrypted copy of the faces it needs, then keeps it up to date in the background. Revoking the token wipes the device's copy at its next sync; a device that can't sync stops verifying after 24 hours.
Never put an API key in an app. Device tokens can only download one group's or event's faces, and nothing else.
5. Check the paperwork#
You're the controller of your users' face data, and FacePing is your processor. Before launch, publish a face check-in privacy notice, offer a way in that doesn't use face check-in, and keep a DPIA. Our templates are in Privacy and compliance.