Revolut starts face payments in London two weeks after leaking customers' selfies

25.09.2026 6 min 45

Revolut is running its first face payment pilot in the UK. From 24 to 26 September, customers at three Kiss the Hippo cafes in London can pay by looking at a camera on the till: no card, no phone. The system compares the face at the counter with the selfie the customer submitted when they opened the account.

That last detail is the story. Two weeks earlier the same bank admitted it had handed over customer passports, selfies and transaction histories in response to a request from a government agency that turned out to be fake.

In short

  • Pay with Smile is opt-in, runs on Revolut's own Register terminals and matches against the sign-up selfie.
  • Revolut says the face template is deleted once the sale clears and that merchants store nothing.
  • The risk is not the till. It is the enrolment selfie, which sits with the bank and has already leaked once.
  • A password can be changed after a breach. A face cannot.

How the pilot works

Customers turn the feature on themselves in the Revolut app, so nobody is scanned for walking in. At the counter they tap Pay with Smile on a Revolut Register terminal and the camera performs an identity check of the kind a phone does when it unlocks. If the match clears the threshold, the payment goes through. If it does not, the till falls back to a card, a phone or Revolut Pay.

The commercial part is as interesting as the biometrics. Revolut is charging the cafes zero processing fees on these transactions, which is how a payments company buys its way onto a counter. Alex Codina, general manager of merchant payments at Revolut Business, framed it as replacing "outdated, fragmented tills with a hyper-efficient checkout experience". Alex Damgaci, managing director at Kiss the Hippo, says the chain plans to extend it to all 12 of its cafes later this year.

3London cafes in the pilot, in Bloomsbury, Soho and Chelsea
12locations the chain plans to cover by the end of the year
0%processing fees Revolut charges on these payments

The data handling is better than the headline suggests

It is worth being fair about the design, because "bank scans your face" invites a reaction that the technical details do not quite support. Revolut says the facial embeddings used to complete a transaction are deleted immediately after the sale is confirmed, that merchants keep nothing, and that processing happens inside its own environment rather than being handed to a third-party vendor. The company also says the biometric data is encrypted end to end.

That is a more careful arrangement than the average retail face recognition deployment, where the awkward questions usually start with which contractor holds the images. Here the answer is that the bank holds them, which is both the reassuring part and the problem.

Why the timing matters

On 12 September Revolut notified affected customers that it had disclosed personal data, including passport images, selfies and transaction histories, after receiving a spoofed request purporting to come from a government agency. We covered it at the time: the request was fake, the data was real. Days later a second incident surfaced through the American broker DriveWealth, which we also wrote about.

The selfie that Pay with Smile matches against is the same class of document that left the building in September. Deleting the till-side template is good hygiene and does nothing about that. The enrolment image has to persist somewhere for the comparison to be possible at all, and the question a customer should be asking is not what happens at the counter but what happens to the copy the bank already holds.

This is the structural difference between biometrics and every other credential. After a breach you rotate a password, reissue a card, change a phone number. A face is not reissuable, and its usefulness to an attacker does not expire. The same logic turned up when India made biometric checks mandatory for SIM cards: convenience arrives first and the irreversibility is discovered later.

The legal frame, briefly

Under UK data protection law a face used to identify someone is special category biometric data, which needs a condition beyond an ordinary lawful basis. The Information Commissioner's Office says explicit consent is usually the most appropriate one, and sets a high bar for what counts: the choice has to be genuinely free, specific and informed, set apart from the general terms.

A voluntary opt-in in an app, for a payment method that has an obvious alternative at the same till, fits that test reasonably well. It would stop fitting the moment face payment became the default, the fast lane or the only queue that moves, which is the direction these pilots usually travel.

  • It is off unless you enable it, and the till still takes a card or a phone
  • The comparison uses the selfie already held from your account opening, not a new one
  • Revolut says the checkout template is deleted after each sale and merchants keep nothing
  • What persists is the enrolment image with the bank, which is the part a breach reaches
  • Ask yourself whether you would still enable it if the same data left the building twice more
Can I be charged by face without agreeing to it?
No. The feature is off until you switch it on in the Revolut app, and a customer who has not enabled it pays the usual way.
Does the cafe keep my face?
Revolut says merchants store no personal data and that the template used for the match is deleted once the sale is confirmed. The enrolment selfie stays with the bank.
What is the actual risk then?
Not the camera at the till. It is that the image used for matching is the same kind of identity document Revolut disclosed in September after a forged agency request, and a face cannot be reissued after it leaks.
Is this legal in the UK?
Biometric identification is special category data and generally requires explicit consent, which the ICO says must be free, specific and informed. A voluntary opt-in with a working alternative at the same counter is the configuration most likely to satisfy that.
Is this spreading beyond a test?
The pilot ran at three cafes over three days, and the chain says it intends to cover all 12 of its locations this year. Nothing has been announced beyond that chain.

united kingdomlondonrevolutbiometricsfacial recognitionpaymentsbanksfintechprivacypersonal datadata leakconsentsurveillance

Read also