84 Total
22 High severity
50 Medium severity
12 Low severity

Key Facts

What right does Affirm reserve?
Affirm reserves the right to close or limit access to your account should you opt out of the crucial notices that are required to perform the Affirm Service.
When may Affirm close or limit access to your account?
Affirm reserves the right to close or limit access to your account should you opt out of the crucial notices that are required to perform the Affirm Service.
What may Affirm's advertising activities constitute under the CCPA?
Affirm's advertising activities involving collection of user internet browsing data for behavioral advertising may constitute a 'sale' or 'sharing' of Personal Information under the CCPA.
What financial account information does Affirm collect?
Affirm collects financial account information including bank account online login credentials, account numbers, transaction history, routing numbers, debit card numbers, and credit card numbers linked to a user's Affirm account.
Does Affirm collect bank account online login credentials and account numbers?
Affirm collects financial account information including bank account online login credentials, account numbers, transaction history, routing numbers, debit card numbers, and credit card numbers linked to a user's Affirm account.
What information does Affirm collect when a user creates an account?
Affirm collects identity and profile information including full name, date of birth, Social Security number, email address, mailing address, phone number, password, and account preferences when a user creates an account.
When does Affirm collect identity and profile information including full name, date of birth, and Social Security number?
Affirm collects identity and profile information including full name, date of birth, Social Security number, email address, mailing address, phone number, password, and account preferences when a user creates an account.
What right does Affirm reserve?
Affirm reserves the right to close or limit access to your account should you opt out of the crucial notices that are required to perform the Affirm Service.
When may Affirm close or limit access to your account?
Affirm reserves the right to close or limit access to your account should you opt out of the crucial notices that are required to perform the Affirm Service.
What does Affirm share user information for?
Affirm shares user information for everyday business purposes including processing transactions, maintaining accounts, offering or servicing loans or lines of credit, offering other financial services, responding to court orders and legal investigations, and reporting to credit bureaus.
Stay ahead of the changes
Track Affirm and get the diff the day its terms change.
Summary

Affirm's Privacy Policy describes what personal information Affirm collects about you — including your Social Security number, bank login credentials, and payment card numbers — how it uses that information, and who it shares it with, including merchants, fraud prevention services, and credit bureaus. You can opt out of Affirm sharing your information with merchants for marketing purposes by updating your Data Sharing setting in your Affirm account, but if you opt out of certain notices Affirm considers essential to its service, Affirm may close or restrict your account. Affirm uses your information for AI and machine learning tools and its behavioral advertising practices may count as selling or sharing your personal information under California law.

Analysis

Affirm's Privacy Policy establishes the scope of personal information Affirm collects, the purposes for which it uses that information, the parties with whom it shares it, and the rights users hold over their data. Affirm collects highly sensitive identity and financial account information — including Social Security numbers, bank login credentials, account numbers, routing numbers, and payment card numbers — and uses this information for transaction processing, account maintenance, lending, research, product development, and AI and machine learning applications. Affirm shares user information broadly across everyday business purposes, including credit bureau reporting, legal compliance, fraud prevention via third-party providers, and merchant marketing, with user consent to merchant marketing sharing treated as given upon acceptance of the Notice and use of the Services. Users hold an opt-out right for nonaffiliate marketing sharing, exercisable through account Data Sharing settings, but Affirm reserves the right to close or limit account access if a user opts out of notices Affirm considers required to perform its service. Affirm's behavioral advertising activities involving collection of internet browsing data may constitute a sale or sharing of Personal Information under the CCPA, and Affirm honors legally required browser-based opt-out signals such as GPC while not recognizing Do Not Track signals.

What this means for you

This document means that Affirm holds some of the most sensitive personal and financial information a user can share — including Social Security numbers, bank login credentials, full account numbers, and payment card details — and flows that information to a wide range of third parties including merchants, fraud prevention providers, credit bureaus, and nonaffiliated marketing companies as a routine part of its operations. Accepting Affirm's Notice and using its Services is treated as consent to Affirm sharing your information with merchants you interact with for their marketing purposes. To limit this, you can log into your Affirm account and update your Data Sharing setting to opt out of merchant marketing data sharing. Be aware that opting out of notices Affirm considers required to perform its service may result in Affirm closing or restricting your account access.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

3 important changes detected

5 versions captured · Last updated: July 2026

What changed Affirm expanded its browser extension data collection disclosures and added Individual Taxpayer Identification Number (ITIN) to the types of personal information it may collect. The updated privacy notice now specifies that the browser extension may collect merchant webpage information including cart contents, product details, pricing, and page URLs when enabled, and states this data is used to provide extension features and personalized experiences. Previously, the notice only mentioned collecting the domain of visited websites. Users can now limit collection through settings, disabling the extension, uninstalling it, or hiding it.
Why this matters The updated privacy notice specifies that Affirm's browser extension may collect merchant webpage data including website domain, page URL, cart contents, product details, pricing, and quantities when you use the extension or in-app browser. The policy clarifies that collected information is used to provide and improve extension features, deliver personalized experiences, and support related services. The notice now also identifies Individual Taxpayer Identification Number (ITIN) as a type of personal information Affirm may collect. You can limit or stop collection by disabling the extension in browser settings, uninstalling it, hiding it, or choosing not to use the in-app browser where an alternative is available.
View full change record →

June 3, 2026

medium
What changed Affirm substantially expanded its Privacy Policy on June 3, 2026, adding over 200 sentences of new disclosure and structural content. The updated policy explicitly identifies Affirm as a financial institution under the Gramm-Leach-Bliley Act, clarifies that certain personal information is governed by federal banking law rather than state privacy laws, and adds detailed sections explaining how Affirm collects, uses, and discloses information, including new disclosures about sharing with fraud prevention and identity verification providers. The previous version lacked this regulatory framing and level of operational detail.
Why this matters The updated Privacy Policy establishes that Affirm qualifies as a financial institution under the Gramm-Leach-Bliley Act, meaning personal information collected in connection with Affirm services is governed by federal banking law rather than applicable state privacy laws. The policy now explicitly discloses collection of identity and profile information including full name, date of birth, Social Security number, email, mailing address, phone number, and password. The updated terms also disclose new data sharing arrangements with fraud prevention, identity verification, and risk intelligence providers, which were not previously detailed. You can contact Affirm's privacy team using the phone number provided in the updated policy to exercise data privacy rights.
View full change record →

June 2, 2026 low

Affirm updated the marketing language describing its products and features on the privacy policy's app download section. The previous text highlighted account management and payments; the updated language emphasizes purchasing …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

84 provisions
12 featured
12 clause types
22 high severity
Data Sharing 23 7 high
Show all 23 data sharing provisions
AI / Automated Decision-Making 1 1 high
General Contract Terms 1 1 high
Liability Limitation 1 1 high
Stay ahead of the changes

Monitoring

Affirm has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Account closure after SMS opt-out of crucial notices and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 30, 2026 00:27 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000168
Version ID CA-V-005353
SHA-256 9b1eb0a0311169706fd223ad0b38988fb0ae4f9adcf00e2927a21272bfe1efb3
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans