Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that ClickUp shares user data with third parties for analytics, error tracking, and marketing, and that outside contractors including hosting providers, credit card processors, and mailing list services may access personally identifiable information in the course of providing services to ClickUp.
This analysis describes what ClickUp's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision identifies the categories of third parties that receive user data and the stated purposes for sharing, which are relevant to CCPA sharing definitions and GDPR data processor and controller determinations. The policy requires contractors to protect personal data consistent with the Privacy Policy or Data Protection Addendum and to use it only for contracted purposes.
Interpretive note: Whether data shared with advertising and market research partners constitutes sharing under CPRA's cross-context behavioral advertising definition depends on specific data flows not fully enumerated in the policy.
The updated policy now explicitly recognizes eight distinct data subject rights, including rights to access, correct, delete, restrict processing, receive data in portable format, object to processing, withdraw consent, and lodge complaints with regulators. Previously, ClickUp described privacy controls through general opt-out options and data access procedures without formal legal framing. The revised language aligns with GDPR and similar data protection frameworks, providing clearer legal reference points for how users may exercise control over their personal data. You can exercise these rights by contacting ClickUp's support team.
View change record →Under this provision, personally identifiable information including identifiers and usage data may be accessed by outside contractors providing hosting, payment processing, and mailing services, and shared with analytics and marketing partners. The agreement requires these parties to limit use to contracted purposes and to comply with the policy's privacy standards.
Cross-platform context
See how other platforms handle Third-Party Data Sharing with Analytics, Marketing, and Contractor Partners and similar clauses.
Compare across platforms →Monitoring
ClickUp has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"The only data we share with third parties is for analytics, error tracking, and marketing. We may employ independent contractors, vendors and suppliers (collectively, 'Outside Contractors') to provide specific services and products related to the ClickUp Service, such as hosting, credit card processing and fraud screening, and mailing list hosting for the ClickUp Service. In the course of providing products or services to us, these Outside Contractors may have access to information collected through the ClickUp Service, including your personally identifiable information.Excerpt from ClickUp's Privacy Policy
REGULATORY LANDSCAPE: This provision engages GDPR Article 28 (processor obligations), CCPA and CPRA definitions of sharing and service provider relationships, and FTC Act standards for data handling representations. The characterization of advertising and market research partners as recipients of shared data, rather than as service providers, may require evaluation under CPRA's definition of sharing for cross-context behavioral advertising, which could trigger opt-out obligations regardless of whether a sale occurs. GOVERNANCE EXPOSURE: Medium. The policy asserts that sharing with marketing partners does not constitute a sale, but CPRA's sharing definition may capture data disclosed to advertising partners for behavioral advertising purposes. Enterprise compliance teams should assess the specific data flows and partner relationships to determine whether opt-out mechanisms are required. JURISDICTION FLAGS: California residents are most directly affected by CPRA sharing definitions. EU and EEA users are affected by GDPR processor and controller obligations applicable to subprocessors. The Data Protection Addendum is identified as the governing instrument for subprocessor relationships with enterprise customers. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should request and review the Data Protection Addendum to identify specific subprocessors, their locations, and the data they access. The policy requires contractors to agree to privacy protections but does not enumerate specific subprocessors in the policy itself, which may not satisfy GDPR Article 28 transparency requirements without the DPA. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data mapping exercise to identify all third-party recipients of personal data, assess whether marketing partner relationships constitute sharing under CPRA, and verify that the Data Protection Addendum includes appropriate Standard Contractual Clauses or equivalent transfer mechanisms for international subprocessors.
This provision identifies the categories of third parties that receive user data and the stated purposes for sharing, which are relevant to CCPA sharing definitions and GDPR data processor and controller determinations. The policy requires contractors to protect personal data consistent with the Privacy Policy or Data Protection Addendum and to use it only for contracted purposes.
Under this provision, personally identifiable information including identifiers and usage data may be accessed by outside contractors providing hosting, payment processing, and mailing services, and shared with analytics and marketing partners. The agreement requires these parties to limit use to contracted purposes and to comply with the policy's privacy standards.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ClickUp.