1. Purpose
This Age Verification Policy (the "Policy") describes how Allospend Technologies LLC ("Allospend," "we," "us") verifies that every user of the Allospend consumer service and the Allospend iOS mobile application (the "Service") is at least 18 years old, and how we respond if we discover that a minor has registered. The Policy is part of the Terms of Service and the Privacy Policy.
2. Why We Verify Age
The Service is a money-routing and group-spending platform that involves financial transactions, premium subscriptions, NFC hardware sales, and AI Features, and is subject to U.S. federal and state laws that prohibit or restrict minors from entering into contracts, transmitting funds, or using certain online services. Specifically:
- The Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 ("COPPA") prohibits us from knowingly collecting Personal Information from children under 13.
- The Federal Trade Commission COPPA Rule, 16 CFR Part 312, requires verifiable parental consent for the limited circumstances in which we might knowingly collect information from a child.
- GDPR Art. 8 and the UK GDPR prohibit the processing of children's Personal Information on the legal basis of consent below age 16 (or the equivalent age in each member state).
- The California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 et seq.) ("CCPA") requires opt-in rights for sale of Personal Information of consumers under 13 and conditional rights for consumers under 16.
- Payment processor terms (Stripe, Plaid, Cash App, PayPal) require that accountholders be at least 18.
- The Bank Secrecy Act (31 U.S.C. §§ 5311–5336) requires us to verify customer identity.
For all of these reasons, the Service is not available to anyone under 18.
3. The 18+ Age Gate
Access to the Service is gated by an age screen at signup. The user must:
- Self-declare their date of birth using a native iOS
DatePickerwhose maximum date is set to eighteen (18) years before the current date. This prevents a user from entering a date of birth in the future or that would make them younger than 18. - Confirm affirmatively that they are at least 18 by tapping an "I am 18 or older" button.
- Accept the Age Verification Policy, the Terms of Service, the Privacy Policy, and the E-Sign Consent before account creation.
A self-declaration alone does not satisfy our verification obligations. We use layered checks (Section 4) before permitting higher-risk features.
4. Layered Verification
4.1 Self-Declaration at Signup
At signup, the user provides their date of birth, name, and email. We compute an age at the moment of signup and reject the registration if the user is under 18.
4.2 Secondary Verification Before High-Risk Actions
Before any of the following, we require a second, independent verification step:
- The first withdrawal to a new bank account.
- Any withdrawal of $250 or more in a rolling 7-day period.
- Instant-withdrawal feature activation.
- Premium subscription purchase above $50 in a rolling 30-day period.
- NFC sticker purchases exceeding $100 in a rolling 30-day period.
- Any transaction flagged by our risk-scoring engine.
Secondary verification is performed by Stripe Identity (government-ID + selfie liveness) or Plaid Identity Verification. These providers return an age attestation (e.g., "21+", "18+") that we use to confirm eligibility. We do not store the underlying government ID image beyond what our providers store under their own retention rules; we store the verification result and provider reference ID.
4.3 Ongoing Behavioral and Risk Monitoring
We continuously monitor accounts for usage patterns consistent with a minor, including:
- Repeated, unsuccessful signup attempts.
- A registered email or display name that suggests a minor (e.g., school email domain, age-revealing self-description).
- Reports from other users, in-app trust-and-safety reports, or third parties.
- Spending patterns consistent with school-aged or college-aged users.
- Cross-account linkage to a known minor's device (e.g., shared device fingerprint, shared IP).
When our monitoring identifies a likely-minor account, the account is automatically routed to human review (Section 5).
5. Flag-and-Review Workflow
When an account is flagged:
- The account is immediately placed in restricted mode (no new transactions, no withdrawals, no NFC sticker activation).
- A trained trust-and-safety agent reviews the verification record, the user-provided date of birth, the secondary-verification result, and the usage signals.
- If the agent determines the user is under 18, the account is suspended immediately and the user is notified by email and in-app that the account has been closed for ineligibility.
- The minor's Personal Information is deleted within thirty (30) days, except where retention is required to comply with anti-fraud, anti-money-laundering, or sanctions-screening obligations (e.g., 31 CFR § 1010.430), or to cooperate with law enforcement.
6. Detection and Deletion Timeline
If we become aware — through monitoring, a report, or self-disclosure — that a user is under 18, we:
- Suspend the account within 24 hours of detection.
- Delete the minor's Personal Information from our production systems within 30 days, except for records we are required to retain.
- Notify the user (or, where appropriate, a parent or guardian) of the deletion.
- Refund any Premium subscription fees on a pro-rata basis to the original payment method.
7. Reporting a Minor on the Platform
If you believe a user of the Service is under 18, you may report it:
- In-app: use the "Report user" or "Report account" action on the relevant profile.
- Email: privacy@allospend.app, with the subject line "Under-18 Report" and any evidence (screenshots, transaction IDs, profile URL).
- Mail: the address below.
We do not commit to review anonymous tips, but we will treat identifying reports as confidentially as the law permits. We do not retaliate against good-faith reporters.
8. No Differential Treatment by Age Above 18
Because access is restricted to users 18 and older, we do not impose further feature restrictions based on age within that adult population. All adult users receive access to the same features (subject to standard verification, risk, and eligibility criteria).
9. International Equivalents
If we extend the Service outside the United States, we will adapt our age-verification practices to comply with local minimum-age laws, including:
- GDPR Art. 8 (EEA / UK) — minimum age 16, unless a member state lowers it to 13.
- Australia: the Online Safety Act 2021 (Cth) and applicable state/territory laws.
- Canada: the Personal Information Protection and Electronic Documents Act ("PIPEDA") and the Age of Majority and Accountability Act of the relevant province.
For EU/UK/CH residents: the Service is not currently directed to those regions; see our Privacy Policy.
10. No Marketing to Minors
We do not knowingly market the Service to anyone under 18. Our paid acquisition channels and organic-marketing channels (e.g., Apple Search Ads, social) are configured to exclude users under 18 where the channel supports such exclusion. Marketing emails to registered users include an unsubscribe link as required by CAN-SPAM (15 U.S.C. § 7701 et seq.) and (for EU users) GDPR Art. 7(3).
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated in accordance with the Terms of Service.
12. Specific Compliance Frameworks
12.1. COPPA (15 U.S.C. §§ 6501–6506) and 16 CFR Part 312
The Service is not directed to children under 13, and we do not knowingly collect Personal Information from a child under 13. To the extent any data is inadvertently collected from a child under 13, we treat it as a COPPA-covered incident: we delete the data within 30 days and document the incident, the source, the data categories, and the deletion evidence.
12.2. GDPR Art. 8 (EEA/UK)
The Service is not currently directed to the EEA, the UK, or Switzerland. If we extend the Service to the EEA/UK, we will implement an age-verification mechanism consistent with GDPR Art. 8 and the relevant member-state law (typically a 16-year threshold, lowered to 13 in some states), including verifiable parental consent where the data subject is below the threshold.
12.3. CCPA / CPRA
Under Cal. Civ. Code § 1798.120(c), the Personal Information of consumers under 13 cannot be sold or shared without verifiable parental consent. Under § 1798.120(c)(2), the Personal Information of consumers aged 13 to 15 cannot be sold or shared without the consumer's opt-in. Allospend does not sell or share Personal Information; these provisions are not currently triggered, but the age-verification Policy ensures we can identify such users if our practices change.
12.4. Missouri Minor-Contract Law
Under Mo. Rev. Stat. § 431.055 and the common-law doctrine of incapacity, contracts entered into by minors are voidable. Our age-verification practices and immediate-suspension workflow are designed to prevent minors from binding themselves to the Terms of Service, the Premium subscription, the Fee Schedule, or any other Agreement.
12.5. Section 5(1) of the FTC Act (15 U.S.C. § 45)
We do not engage in unfair or deceptive acts or practices with respect to minors. Our marketing channels exclude known-minor audiences where the channel supports it, and we do not use dark patterns to elicit consent from any user.
13. No Use for Age Estimation of Other Users
You may not use the Service to estimate or assert the age of another user. Do not upload images of other individuals to the OCR or AI Features for the purpose of age estimation. Doing so is a violation of our Acceptable Use Policy and may also violate the Illinois Biometric Information Privacy Act (740 ILCS 14) if it triggers the collection of biometric identifiers without consent.
14. Interaction with Biometric Consent
Where age verification involves a selfie-based liveness check (e.g., Stripe Identity), the selfie is processed by our sub-processor and is not stored by Allospend. The sub-processor's retention rules govern the biometric data, consistent with our Privacy Policy Section 7.
15. Severability and Survival
If any provision of this Policy is held invalid or unenforceable, that provision will be enforced to the maximum extent permitted by applicable law and the remaining provisions will remain in full force and effect. Provisions that by their nature should survive — including the suspension and deletion obligations, the law-enforcement cooperation clause, and the recordkeeping requirements — survive any termination of your account.
16. Relationship to Other Agreements
This Policy supplements, and does not replace, the Terms of Service, the Privacy Policy, the Acceptable Use Policy, the AI Terms, the E-Sign Consent, the Fee Schedule, and the Auto-Renewal Disclosure. In the event of a conflict between this Policy and the Terms of Service specifically with respect to age eligibility, this Policy controls. Capitalized terms not defined here have the meanings given in the Terms of Service.
17. Worked Examples
The following examples illustrate how the Policy operates:
- Example A — Adult user (24) with selfie verification. Self-declared DOB at signup places them above 18. A first withdrawal triggers Stripe Identity; the provider returns an "18+" attestation. The withdrawal is approved.
- Example B — User self-declares DOB making them 17. The signup form rejects the registration because the
DatePickermaximum is set to 18 years ago. No account is created. - Example C — User self-declares 19 at signup but ID check returns "under 18". The account is suspended within 24 hours; the user is notified; PI is deleted within 30 days; Premium fees are refunded pro-rata.
- Example D — Account flagged by behavioral signals (school email domain, age-revealing username). The account is moved to restricted mode; a human agent reviews; if confirmed under 18, the account is suspended and PI deleted within 30 days.
- Example E — User reports another user they believe is a minor. The reporter uses the in-app "Report user" action. The reported account is moved to restricted mode; an agent investigates; if confirmed, the account is suspended and PI deleted.
18. Contact for Parents and Guardians
If you are a parent or legal guardian of a child who you believe has registered for the Service, contact us at privacy@allospend.app with:
- Your name and contact information.
- The child's name and any account ID or email address you have.
- Evidence supporting the claim (e.g., copy of the child's birth certificate or government ID showing the date of birth).
We will respond within 5 business days. If we confirm the account belongs to a minor, we will suspend the account, delete the minor's PI within 30 days, and refund any Premium fees on a pro-rata basis to the original payment method.
Contact Information
- Privacy / Data Protection Officer: privacy@allospend.app
- Customer Support: support@allospend.app
- Legal: legal@allospend.app
- General Information: info@allospend.app
- Compliance / AUP reports: compliance@allospend.app
- Disputes: disputes@allospend.app
- App Store: https://apps.apple.com/app/allospend-group-finances/id6795749022
- Domain: https://allospend.app
Allospend Technologies LLC
725 Kingsland Avenue, Suite 100
St. Louis, MO 63130
USA
© 2026 Allospend Technologies LLC. All rights reserved.