After that they have: my face, copy of my passport, my voice, my phone number, my IP (unless I'm really going out of my way to obfuscate it), my email, etc.
Once I did this, then the series of documents to sign using Docusign came in.
That was the most serious KYC/AML I've ever seen.
I don't like it much but I gotta say: I can definitely see how it raises the bar for would be scammers/impersonators.
MasterCard and their "True Name" program did a good thing there.
As more commerce moves online, Stripe Identity was built to significantly reduce the number of organizations and humans that would touch your ID—in a faster, secure way that’s hosted by Stripe (https://support.stripe.com/questions/common-questions-about-...).
We are also very direct about collecting consent: https://support.stripe.com/questions/common-questions-about-....
And as we've all come to know the distinction between "able to surveil" and "collect it all" crosses a threshold to make it of a different kind.
If one's mindset is that in general, tech companies, unlike those other entities store it all, then there actually is a recent "trend" to migrate a normal behavior into an abnormally socially adjusted space.
> As more commerce moves online
It is very much a trend and that is very much what you are describing. The problem with identity verification is
a) Business that have no business requesting them do so. Linkedin, Google, Facebook does this when they suspect you are a bot. But if you have been a long time user, they hold your account with your personal data as hostage. You cannot delete your account if you object to providing your official documents.
b) There is very little legal protection if companies (not saying Stripe will) use your official documents to build an extremely detail online profile of you. Its all based on trusting what these companies say.
Maybe these things are designed for KYC’ing crypto and buying alcohol but it’s definitely a trend to apply this process broadly. All for the fear of generally preventing everyday fraud, piracy, and maybe just collecting data for some nebulous future use. Of course they rarely do the actual basics and apply any thought to not treating your real customers like criminals.
I don’t doubt Stripe can make the process better and do it in a good way, but can Stripe minimize what this process is even applied to in the first place and avoid manufactured consent.