Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that by using Betterment's services, customers acknowledge and agree that the privacy policies of multiple third-party providers, including Socure, Plaid, Stripe, MX Technologies, Apex Clearing, Ascensus, and Capitalize, govern those providers' use of customer data, and in some cases expressly grants those providers the right, power, and authority to access, store, and transmit customer information.
This analysis describes what Betterment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that data governance for a material portion of customer information is delegated to the terms of multiple third-party providers, and in the case of Plaid and Stripe, customers expressly authorize those providers to access and transmit their financial and payment information under those providers' own privacy frameworks.
The updated policy discloses a new Fully Paid Securities Lending program through Apex Clearing, under which Betterment will share customer personal information and account details with Apex if customers choose to participate. The revised terms also establish that generative AI service providers have committed that personal information will not be used for model training. For customers participating in promotional offers requiring offline fulfillment, the policy now explicitly states that personal information including mailing address may be shared with third-party partners. You can review the FPSL Program supplemental disclosures for details about the securities lending arrangement, or choose not to participate in the program.
View change record →Under these clauses, the agreement incorporates by reference the privacy policies of Socure, Plaid, Stripe, MX Technologies, Apex Clearing, Ascensus, and Capitalize, meaning customers are bound by the data practices of each provider for information processed through those services, in addition to Betterment's stated commitments.
Cross-platform context
See how other platforms handle Third-Party Provider Privacy Policy Delegation (Plaid, Stripe, Socure, MX, Apex, Ascensus) and similar clauses.
Compare across platforms →Monitoring
Betterment has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"By creating an account with Betterment, you acknowledge and agree that the terms of Socure's Privacy Policy will govern Socure's use of such information. Betterment offers account linking and aggregation services through Plaid Inc. ('Plaid'). By using account linking and aggregation services, you acknowledge and agree that the terms of Plaid's Privacy Policy will govern Plaid's use of such information, and you expressly agree to the terms and conditions of Plaid's Privacy Policy. Further, you expressly grant Plaid the right, power, and authority to access and transmit your information as reasonably necessary for Plaid to provide these services to you. Betterment uses Stripe, Inc. ('Stripe') to process customer payments. By using these payment services, you acknowledge and agree to the terms of Stripe's Privacy Policy. Further, you expressly grant Stripe the right, power, and authority to access, store, and transmit your payment information as reasonably necessary for Stripe to provide these services to you.Excerpt from Betterment's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GLBA requirements for financial institution data sharing with service providers, CCPA/CPRA service provider and contractor classification requirements, and FTC Act authority over data handling representations. For Plaid specifically, the FTC has previously reviewed data aggregator practices in the context of financial data access. CFPB open banking regulations and data rights frameworks may also apply to account linking and aggregation services. GDPR Article 28 would require documented processor agreements for any EU-connected data flows. 2) GOVERNANCE EXPOSURE: Medium. The delegation of privacy governance to multiple external providers through acknowledgment clauses rather than direct data processing agreements visible to the customer creates a fragmented compliance posture. Betterment states it enters into confidentiality agreements with service providers, but the scope and enforceability of those agreements relative to each third party's own privacy policy is not disclosed in this document. 3) JURISDICTION FLAGS: California (CCPA/CPRA service provider and contractor requirements), EU/EEA (GDPR processor agreement requirements), and Illinois (BIPA, if facial image collection by Socure involves biometric identifiers) create heightened exposure. Socure's collection of facial images and selfie photographs for identity verification may trigger BIPA obligations in Illinois and analogous biometric privacy laws in Texas and Washington. 4) CONTRACT AND VENDOR IMPLICATIONS: The explicit grant of 'right, power, and authority' to Plaid and Stripe to access and transmit customer financial and payment information is a material contractual delegation. Procurement and legal teams should assess whether Betterment's service agreements with these providers include data use limitations consistent with Betterment's stated confidentiality commitments and applicable law, including prohibitions on secondary use. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data mapping exercise covering all named third-party providers to confirm data categories, retention periods, and permissible use restrictions; assess whether biometric data collection through Socure triggers state biometric privacy law obligations; review whether Plaid and Stripe are classified as service providers or independent controllers under applicable state law; and determine whether customer-facing disclosures are sufficient to satisfy informed consent requirements for each delegated data relationship.
This provision establishes that data governance for a material portion of customer information is delegated to the terms of multiple third-party providers, and in the case of Plaid and Stripe, customers expressly authorize those providers to access and transmit their financial and payment information under those providers' own privacy frameworks.
Under these clauses, the agreement incorporates by reference the privacy policies of Socure, Plaid, Stripe, MX Technologies, Apex Clearing, Ascensus, and Capitalize, meaning customers are bound by the data practices of each provider for information processed through those services, in addition to Betterment's stated commitments.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Betterment.