FareHarbor blocks file uploads that contain personally identifiable information (PII), including driver's licenses, passports, national ID cards, bank cards, and similar documents. This protects your customers and helps you comply with data protection laws in the US, Europe, and other regions.
FareHarbor is designed for bookings and operations. It is legally not allowed to store sensitive information or identity documents. You are responsible for how you collect, store, and retain guest documents required for insurance, rentals, or local regulations.
What uploads may be blocked by FareHarbor?
Uploads in FareHarbor may be blocked if they contain any of the following:
- A full name combined with a government-issued ID number
- Images of driver’s licenses or passports
- A date of birth combined with an identification document
- Social Security numbers (SSNs), tax identification numbers, or national insurance numbers
- Credit card numbers or bank account details
The following are examples of what is allowed in FareHarbor: activity photos, marketing images, insurance certificates for your business (not guest IDs).
Why can’t I upload driver’s licenses or passports to FareHarbor?
FareHarbor blocks driver’s license and passport uploads because it is not designed to store sensitive identification documents.
You may need to collect these documents for:
- Vehicle or equipment rentals
- Insurance requirements
- Age or eligibility verification
- Local regulatory compliance
Although these uses may be legitimate, storing identification documents in FareHarbor can conflict with GDPR data-minimization principles and create obligations under U.S. state privacy laws.
Recommended alternatives
Option 1: Use secure business storage
- Use an approved business storage service with encryption, role-based access, and activity logging.
- Create a secure, access-controlled upload request for each booking. Guests must not be able to view files uploaded by others.
- Send the upload link in your pre-arrival email. Do not upload the document to FareHarbor.
- Establish a retention period based on applicable legal, insurance, and business requirements, and delete the document when it is no longer needed.
Important: Your business is responsible for selecting, configuring, and managing the storage service and its privacy controls.
This approach gives your business greater control over access and retention.
Suggested guest-facing template:
To prepare for your activity, please upload your driver’s license securely here: [link]. We will use it only to verify your eligibility for [activity] and delete it within [X] days after your activity. For more information, see our privacy policy: [link].
Option 2: Verify the document in person
- Ask the guest to bring the original document to check-in.
- Confirm that:
- The name matches the booking
- The photograph matches the guest
- The document is valid and has not expired
- In the FareHarbor booking notes, record only:
- ID verified: Yes
- Date verified
- Staff initials
Do not record the document number or upload an image of the document.
This approach limits the personal data you retain and supports:
- GDPR data-minimization and storage-limitation principles: Personal data should be limited to what is necessary and retained only as long as needed (GDPR Article 5).
- Applicable U.S. privacy requirements: For example, businesses subject to the CCPA must limit the collection, use, and retention of personal information to what is reasonably necessary and proportionate (California Privacy Protection Agency).
Privacy and retention requirements vary by jurisdiction. Your business should determine which requirements apply to its activities.
Practices to avoid
- Do not ask guests to send identification documents through standard email or personal messaging accounts.
- Do not store identification-document images in FareHarbor notes, custom fields, or attachments.
- Do not share identification documents through channels that lack appropriate business security and access controls.
- Do not retain documents longer than necessary. Instead, define, document, and enforce a retention schedule.
- Do not collect identification documents from minors unless strictly required by law.
Frequently asked questions (FAQs)
Does FareHarbor detect every type of PII?
We use automated detection for common PII in files. When in doubt, assume the upload will be blocked and use an external workflow and storage.
What if my insurance company requires a copy of the license?
Many insurers require proof of verification, not permanent storage in your booking system. Store copies in your secure storage or via a compliant vendor, with a defined retention period. Confirm requirements with your insurer and legal counsel.
What happens to files I already uploaded?
FareHarbor will delete all uploaded files that contain personally identifiable information after June 2027. These files remain accessible on your FareHarbor Dashboard until June 2027.
Can I paste the link to access the documents I collected on FareHarbor’s booking notes?
Avoid adding Google or shared drive links that contain the booker’s personal identifiable information to FareHarbor booking notes. These links could be seen and accessed by third parties who should not have access, which is considered a privacy or data protection breach.
What regions is the information in this help page relevant to?
The recommendations in this help page are in line with data protection laws in the European Union (EU), United Kingdom (UK), and California. Blocking PII in FareHarbor supports data minimization (GDPR Art. 5) and reduces unauthorized processing risk that might infringe laws in the U.S. and Europe. You remain responsible for lawful collection and storage wherever documents are stored.