Wegmans will tell you, if you ask directly, that it scans shoppers' faces in "a small fraction" of its stores. What it won't tell you is which fraction, whose face matched something, or what happens to the scan of everyone who didn't.
In January 2026, reporting confirmed Wegmans is running facial recognition on customers in its Manhattan and Brooklyn locations, part of a wave of grocery chains quietly rolling out the technology under the banner of "loss prevention." Lowe's has separately admitted to using it to flag suspected shoplifters. And when the ACLU asked the country's biggest retailers a straightforward question — are you doing this? — most of them simply declined to answer.
Who's Doing It, Who's Denying It, and Who Won't Say
Wegmans and Lowe's are the two major chains that have confirmed using facial recognition on customers, framing it narrowly as a tool to identify people already flagged by asset protection teams or law enforcement for theft or missing-persons cases. Lowe's says it doesn't retain data on shoppers whose faces don't match an existing flag.
Ahold Delhaize — the parent company behind Food Lion, Stop & Shop, Giant, and Hannaford — is one of the few major grocery operators to explicitly deny using the technology at all, a useful reminder that this isn't universal across the industry.
Everyone else sits in a much murkier middle: Walmart, Kroger, Costco, Home Depot, CVS, Walgreens, Target, Best Buy, McDonald's, and Macy's all declined to answer the ACLU's inquiry about whether they use facial recognition on customers, citing competitive or proprietary concerns. That's not a denial. For a technology this consequential, "we won't say" functions a lot like "yes, and we'd rather you not think about it."
It's Not Just Your Face
Wegmans' program reportedly goes beyond a simple face match. The company has been reported to collect license plate data, track in-store movement, log IP addresses, and cross-reference purchase history — building a considerably more detailed picture of a shopping trip than "did this face match a shoplifter database." How long any of it is retained is undefined; the company's public position is that data is kept "only as long as necessary," a phrase that describes no actual policy at all.
The Accuracy Problem Nobody's Solved
Facial recognition misidentification isn't a hypothetical risk — it's a documented, recurring one, and it doesn't fall evenly across the population. Independent studies, including federal testing by NIST, have repeatedly found higher false-match rates for women and people with darker skin tones across many commercial facial recognition systems. In a retail context, a false match doesn't mean an inconvenient pop-up. It means being stopped, questioned, or banned from a store you've shopped at for years, based on an algorithm's confidence score rather than anything you actually did.
The Pushback Has Already Started
Connecticut lawmakers have introduced legislation that would ban retail facial recognition outright, joining a small but growing list of states considering restrictions specifically aimed at commercial — not just government — use of the technology. That's a meaningfully different fight than the ALPR and Flock camera pushback covered elsewhere on this blog: those fights target police use of surveillance tech, while this one targets private companies deploying the same core technology against their own paying customers, with essentially no disclosure requirement in most states.
What You Can Actually Do
- Ask directly, in writing, whether a store uses facial recognition. Companies that have a real policy will usually tell you; the ones that dodge the question are telling you something too.
- Look for posted signage at store entrances — some states already require disclosure if facial recognition is in use, and a lack of signage in those states is itself worth reporting to your state attorney general.
- Support state legislation specifically targeting retail use, not just government use — Connecticut's proposed ban is a template other states are watching.
- If you're misidentified, document everything immediately — time, location, staff names, and what you were told — since these cases often turn on there being no independent record beyond the store's own system.
- Consider low-tech countermeasures if you want to reduce your odds of being logged at all, from adversarial apparel designed to interfere with facial detection to simply choosing chains that have publicly confirmed they don't use the technology.
The Other Side
Retailers argue facial recognition is a direct, measurable response to a real problem — organized retail theft has been a genuine and growing cost for grocery and home-improvement chains, and matching known shoplifters against a watchlist is, in principle, narrower and more targeted than blanket surveillance of every customer. Lowe's specific claim — that non-matches aren't retained — is a real distinction from systems that log everyone regardless of match, and if true, it's a meaningfully more limited use case than critics sometimes suggest.
Civil liberties groups respond that "if true" is doing a lot of work in that sentence, given how little independent verification exists for any retailer's retention claims, and that even a narrowly-targeted watchlist system still requires scanning every single customer's face to check for a match — meaning the privacy cost is paid by everyone, guilty or not, every time they walk in. The disagreement here isn't really about whether shoplifting is a real problem. It's about whether scanning a hundred faces to catch one shoplifter is a trade the hundred ever agreed to make.
Sources referenced: State of Surveillance, Biometric Update, the ACLU, and The Spokesman-Review.
Related gear
If you'd rather not be a data point in a retailer's facial recognition database, our Glitchgear Adversarial Fashion tee and Facial Recognition Suppression tee are designed specifically to interfere with these systems. The Ghost Protocol field guide covers your rights if you're ever misidentified.
0 comments