Ask the wallet one question. Is this person over 18. It answers with a signed proof and nothing else. You get a compliance artefact and store a boolean, which is about as little personal data as the obligation allows.
Age gates on restricted storefronts are either useless or invasive. A birth-date dropdown proves nothing and satisfies nobody. A document check works, but it drops conversion at checkout and leaves a wine shop holding identity documents it has no business keeping.
Step 01
Put the check at add-to-cart or checkout. Gating the whole storefront kills your organic traffic for no compliance benefit.
Step 02
We request age_over_18 and nothing more. The shopper sees exactly that on their consent screen.
Step 03
The order carries a signed verification reference. No document, no birth date, nothing that identifies the shopper beyond the order itself.
Rules in play
National alcohol and tobacco sales law, GDPR data minimisation, eIDAS 2.0
Live demo
We built Halcyon Cellars, a company that does not exist, to show this running inside a finished product. The wallet flow in it is the real SDK.
Open the Halcyon Cellars demoBuilt on Authbound Identity Verification. One API key covers every flow you add later.