Probably easier to make it an app that gives each user a unique token and a server side request is sent to request camera permission, employ some basic facial recognition to match the face with the picture/token combo they have to LL, and if the handshake is verified you know you're good, without the client ever seeing or be involved other than initiating the request. Everything could be handled server side and wiped often., And if they aren't willing to point their phone at their face for 3 seconds then you're probably being scammed.