ActiveManage Docs ← Back to activemanage.co.uk

Identity Document and Age Checks

Identity checks are performed by Onfido or Stripe Identity. The user is sent into the provider's own flow, photographs a document, usually takes a selfie, and the provider returns a decision.

What the user experiences

  1. They choose to verify and are sent to the provider — often continuing on their phone, which has a better camera.
  2. They photograph their document and, usually, themselves.
  3. They are returned to your site.
  4. The result arrives from the provider, generally within moments but sometimes after a human review at their end.

Because a result can arrive after the user has returned, your interface should show the check as in progress rather than assuming it has finished.

Age checks

Onfido, Stripe Identity and SheerID can all confirm a user is over a threshold. The threshold is part of the provider's programme configuration, so it is set in the type's programme settings. The date of birth is never copied into ActiveManage — you receive the answer, not the birthday.

What is stored

Only what is needed to act on: the provider's reference, the decision, and a one-line summary of the evidence such as "Passport, GBR". Identity documents, selfies and extracted dates of birth are not copied into ActiveManage — they stay with the provider.

Before switching this on

Collecting identity documents is high-impact processing of personal data. Have your data protection assessment done first, be clear about what you tell users, and settle your retention position — see Security and Data Protection, which describes one record you must set a retention policy for yourself.

Worked Examples

  • Marketplace seller onboarding: ID check before payouts are enabled.
  • Age-restricted retail: age check at checkout, stored for two years so returning customers are not re-asked.
  • Financial services: ID check as part of a wider onboarding process, with manual review on.