^ That is the norm as Zachery said, furthermore they must ask and insist to ensure lol just like Zach said that you're YOU. Yes some have tried some fraudulent stuff in the past this is why its setup that way. As Ozzy mentioned above use the sensitive data field to include such info.
Alternatively, I assuming here but I don't see why you cannot simply ask for the support staffs company email address and then simply scan your ID, throw the file into a .zip and password protect it, now email them the .zip and the password to it so only they can open it - just a suggestion and if anyone does intercept the file somehow its still password protected.
|