Independent Australian consumer reference
Assess a Rainbet identity request before sending documents
Identity checks can expose documents that remain valuable long after an account closes. Before sending anything, establish who will receive it, why each field is needed, how it will be protected and which entity is accountable for deletion or correction.
Research checkpoint:
| Question | Evidence to obtain | Pause signal |
|---|---|---|
| Who receives it? | Controller, processor and confirmed hostname. | Only a brand or chat alias is named. |
| Why is it needed? | Purpose tied to each requested field. | A broad request has no defined task. |
| How is it handled? | Sharing, access, storage and retention terms. | Policy versions conflict or omit the recipient. |
| What can be limited? | Accepted document alternatives and redactions. | Unrelated financial or identity data is demanded. |
| How is misuse reported? | Security contact and incident reference route. | The helper requests more secrets or remote access. |
Evidence step 01
Identify the recipient, not just the brand
Record the legal entity named in the account terms, privacy notice and verification request. Compare its company details, jurisdiction, contact address and data-controller wording across those records. If a separate verification vendor is involved, identify both the business directing the check and the processor receiving the files. A logo, chat username or upload page on a related-looking domain does not establish who is legally responsible for the data.
Verify contact details independently before following an upload link. Inspect the complete hostname, certificate warning state and privacy information, and ask the purported controller to confirm the vendor and submission domain through a previously established channel. Do not send documents to a personal inbox, social account or disappearing message because someone claims the normal portal is unavailable. Keep a dated copy of the request and its sender details.
Evidence step 02
Demand a defined purpose and data list
Ask what account fact each requested item is intended to establish. Age, name, address, payment ownership and source-of-funds questions are distinct tasks and need not justify collecting every visible field. Request the policy basis, retention period, sharing categories and consequences of declining. Vague statements about security or regulation are not substitutes for naming the accountable entity, applicable process and exact information required.
Create a disclosure inventory before uploading. List the document, exposed fields, recipient, submission date and stated purpose. A passport can reveal nationality, birth details, signature and document number; a bank statement can reveal spending, counterparties and account identifiers. Consider whether a less revealing record or properly redacted copy satisfies the defined check. Never alter a document deceptively, but do not expose unrelated information without a clear need.
Evidence step 03
Reduce avoidable identity exposure
Use a trusted device and network, update the browser, and navigate independently to the confirmed submission service. Check that the password manager recognises the hostname. Remove image metadata where appropriate, cover unrelated transactions if accepted, and avoid leaving copies in shared downloads, cloud galleries or scanner apps. Watermarking may help identify the intended use when the recipient permits it, but it does not prevent copying or misuse.
Do not provide email recovery codes, authenticator secrets, wallet keys, card security values or remote-control access as part of identity verification. A selfie request should state why it is needed and how biometric information is handled. If live camera access is requested, inspect permissions and revoke them afterward. Stop if the workflow suddenly moves to another domain, asks for screen sharing or pressures you to bypass device warnings.
Evidence step 04
Check handling, retention and correction rights
Read the privacy notice for storage location, recipients, overseas disclosure, retention triggers, security contacts and procedures for access, correction or deletion requests. Note whether account closure actually starts deletion or whether legal and dispute records are retained separately. If several policies conflict, ask the named controller which version governs the submission. Preserve the answer because a generic footer link can change after documents have been supplied.
Security claims should be testable at the level relevant to your files. Encryption language alone does not identify staff access, vendor permissions, breach response or deletion controls. Ask for a case reference if you request correction or removal. Keep proof of submission without retaining unnecessary duplicate identity images. The goal is a defensible record of what was disclosed and to whom, not a larger archive that creates another exposure point.
Evidence step 05
Act quickly after suspected misuse
If documents went to the wrong recipient, preserve the URL, request, upload confirmation and any message headers. Contact the genuine document issuer, financial institution or identity-support service through independently verified channels as appropriate. Protect the linked email account, change reused passwords, revoke sessions and monitor for altered recovery details. A compromised email account can turn an identity leak into broader account takeover.
Notify the identified data controller and ask it to contain the disclosure, explain access and provide a written incident reference. Reporting options depend on the entity, location and nature of the information, so do not assume a particular authority has jurisdiction until its remit is checked. Continue an incident log and avoid sending a second, clearer document to an unverified helper who claims it is needed to investigate the first exposure.
Questions
Questions for this evidence task
How can I check who will receive my identity documents?
Match the legal entity, privacy controller, verification vendor and upload hostname across independently obtained records before submission.
Can I redact unrelated information from a verification document?
Ask whether a less revealing record or limited redaction is accepted for the defined purpose. Do not make deceptive alterations, and retain the recipient's instructions.
Is a selfie with an identity document low risk?
No. It combines identity and biometric material. Require a clear purpose, accountable recipient, handling policy and secure confirmed channel.
What should I do if I uploaded files to a suspicious page?
Preserve evidence, protect linked accounts, contact relevant issuers through trusted channels and report the incident to the verified controller or suitable authority.