TL;DR: Wegmans scans shoppers' faces in stores across multiple states. They won't say which ones. The database includes people "flagged for misconduct" and photos submitted by law enforcement. NYC required disclosure signs, so we know it's happening in Manhattan and Brooklyn. But Wegmans has 114 stores in 10 states. The ACLU found the company also incorporates law enforcement BOLO (be on the lookout) photos into its system. Macy's and Lowe's do similar things. Most customers walk in with no idea their faces are being cataloged.

What Wegmans Admitted

Wegmans confirmed facial recognition in a "small fraction" of stores [1]. They describe these as locations with "elevated risk." Translation: stores where they've had theft problems.

What the system does:

  • Cameras capture faces of everyone entering
  • Software compares faces against a database of "persons of interest"
  • Database includes people flagged by Wegmans security
  • Database also includes photos from law enforcement
  • Matches trigger alerts for store security

Wegmans claims it doesn't share facial recognition data with third parties. The ACLU questioned how enforceable that promise is when law enforcement photos are already in the database [2].

Where This Is Happening

We only know for certain about two locations: Wegmans stores in Manhattan and Brooklyn. Why? Because New York City requires businesses to post signs if they collect biometric data [3].

That law passed in 2021. It's one of the few in the country.

What we don't know:

  • Which of Wegmans' other 112 stores use facial recognition
  • Whether any stores in Western New York have it (Wegmans won't say)
  • Whether the 17 stores near Rochester (Wegmans' hometown) are included
  • How long they've been doing this

When journalists asked about specific locations, Wegmans refused to answer [4]. A company spokesperson told Investigative Post: "We don't disclose which stores have facial recognition."

The Law Enforcement Connection

Here's where it gets worse. Wegmans acknowledged incorporating law enforcement information "on a case-by-case basis" [2].

The ACLU found that Wegmans scans customers' faces for resemblance not only to accused shoplifters but also to people whose photos have been submitted to the company by law enforcement. The company isn't just catching shoplifters. It's running a surveillance operation with police-supplied targets.

What this means:

  • Police can submit photos to Wegmans' system
  • Your face gets compared against those photos when you shop
  • No warrant required
  • No disclosure to you

Wegmans says it doesn't share the facial recognition data back to police. But they're already receiving data from police. The information flows one direction now. How long before it flows both ways?

Everything Else They're Collecting

An Investigative Post analysis of Wegmans' Buffalo stores found facial recognition is just one part of a larger surveillance apparatus [5].

The full picture:

  • Parking lot: License plate capture before you enter
  • Store entry: Facial recognition cameras at entrances
  • In-store: Ceiling-mounted Axis Communications cameras tracking movement
  • Mobile: Geolocation from phones connecting to store WiFi
  • Checkout: Payment info, purchase history, SNAP benefits data
  • Digital: IP addresses, cookies, browsing behavior

Wegmans' privacy policy states they share "de-identified purchase and profile data" with advertisers including Google and Meta. They're watching you in person and selling data about you online.

It's Not Just Wegmans

The ACLU reached out to nearly 50 major retailers. Most refused to answer. The ones that did reveal a pattern [2].

Retailers confirmed using facial recognition:

  • Macy's: "small subset of stores with high incidences of organized retail theft"
  • Lowe's: confirmed use at some locations
  • Rite Aid: used facial recognition, incorporated police BOLO photos (sued in 2020, system since suspended)

Retailers that said they don't use it:

  • CVS, Target, Stop & Shop, Burlington, Marshalls, TJ Maxx, HomeGoods
  • Walmart, Kroger, Home Depot, Costco, Dollar Tree

Walmart tested facial recognition but stopped. Home Depot tested and stopped. Target is currently facing a BIPA lawsuit in Illinois alleging they use the technology despite denials [6].

The Accuracy Problem

Facial recognition misidentifies people. It happens a lot. It happens more often to women and people of color [7].

At least 10 people have been publicly identified as wrongly accused due to facial recognition errors in retail and law enforcement settings. Those are the cases we know about. How many false matches happen inside Wegmans stores? Nobody's required to report them.

Erie County Executive Mark Poloncarz called retail facial recognition "a serious invasion of privacy" and local legislators are considering disclosure requirements or outright bans [5].

No Federal Law Stops This

There is no comprehensive federal law regulating facial recognition in retail. None.

The patchwork:

  • Illinois BIPA: Individuals can sue over biometric collection without consent
  • Texas CUBI: State biometric privacy law prohibits collection without consent
  • New York City: Requires disclosure signs, but no real enforcement mechanism
  • Portland, OR: Banned facial recognition in private settings
  • Everywhere else: Fair game

NYC's Department of Consumer and Worker Protection admitted it has no enforcement mechanism if companies don't comply with the disclosure law [3]. The sign requirement has no teeth.

What You Can Do

Check for signs: If you're in NYC, look for biometric disclosure signs at store entrances. If there's no sign and they're collecting your data, that's a violation.

Pay cash: Breaks the link between your face and your identity through payment records. Doesn't stop them from scanning you, but limits what they can tie together.

Avoid store WiFi: Don't connect. Don't use store apps while shopping. Your phone is another data point they're collecting.

Know your state laws:

  • Illinois residents can sue under BIPA
  • Texas residents have protections under CUBI
  • Most other states have no recourse

Support legislation: Push for biometric privacy laws in your state. The Illinois model works. That's why companies fear it.

The Bottom Line

Wegmans scans your face when you buy groceries. They include law enforcement photos in their database. They won't tell you which stores do this. And they're far from the only retailer doing it.

This isn't about catching shoplifters. If it were, they'd be transparent about it. They'd post signs voluntarily. They'd answer journalists' questions.

Instead, they stay quiet until a local law forces disclosure. They refuse to say which stores scan faces. They accept photos from police for their database while claiming they don't share data with police.

Your grocery store became a surveillance checkpoint. You just didn't know it.

References

  1. Grocery Dive: Wegmans explains how it uses facial recognition (January 2026)
  2. ACLU: Retailers Secretively Using Face Recognition to Spot "Persons of Interest" (January 2026)
  3. Gothamist. Not just Wegmans: More NYC retailers using facial recognition as tech outpaces law (January 2026)
  4. Central Current: Wegmans won't say if facial recognition planned for Upstate NY (January 2026)
  5. Investigative Post: Wegmans in Buffalo surveilling shoppers, collecting reams of data (January 2026)
  6. CBS New York: Some Wegmans locations using facial recognition software (January 2026)
  7. WXXI News: Wegmans using facial recognition in 'a small fraction' of stores (January 2026)