107 Total
29 High severity
61 Medium severity
17 Low severity

Key Facts

When will Coinbase terminate a user's account?
Coinbase will terminate a user's account if it cannot process that user's personal information for such purposes.
What may Coinbase use automated decision-making to fulfill?
Coinbase may use automated decision-making to fulfill its regulatory and contractual obligations relating to the safety, security, and integrity of its Services.
May Coinbase use automated decision-making to fulfill its regulatory and contractual obligations relating to the safety, security, and integrity of its Services?
Coinbase may use automated decision-making to fulfill its regulatory and contractual obligations relating to the safety, security, and integrity of its Services.
What biometric information does Coinbase collect?
Coinbase collects biometric information generated from photos or videos provided by users for identity verification.
What supplemental identification information does Coinbase collect?
Coinbase collects supplemental identification information including utility bills, photographs and/or videos, government-issued identity documents, and social security or social insurance numbers.
What does Coinbase rely upon ICDR-AAA services for?
Coinbase is a member of and relies upon ICDR-AAA services for unresolved complaints concerning its handling of personal information under the Data Privacy Frameworks, which may involve binding arbitration under certain conditions.
Is Coinbase a member of ICDR-AAA?
Coinbase is a member of and relies upon ICDR-AAA services for unresolved complaints concerning its handling of personal information under the Data Privacy Frameworks, which may involve binding arbitration under certain conditions.
Why does Coinbase retain user information?
Coinbase retains user information as needed to provide its Services, comply with legal obligations, or protect its or others' interests.
Can users opt out of critical service communications sent by Coinbase for legal or security purposes?
Coinbase does not permit users to opt out of critical service communications sent for legal or security purposes.
When may Coinbase transfer user personal information?
Coinbase may transfer user personal information in the event of an acquisition, merger, reorganization, going out of business, bankruptcy, or other change of control or similar event.
Stay ahead of the changes
Track Coinbase and get the diff the day its terms change.
Summary

This document explains what personal information Coinbase collects about you—including sensitive items like biometric data, government IDs, and social security numbers—how Coinbase uses and shares that information, and how long it keeps it. Coinbase may share your data with advertisers such as Meta and AppLovin, and may transfer it to another company if Coinbase is acquired or undergoes a major corporate change. You can ask Coinbase to delete your information, but legal obligations may prevent full deletion, and you cannot opt out of communications Coinbase deems critical for legal or security purposes.

Analysis

The Coinbase Privacy Policy establishes the categories of personal information Coinbase collects—including biometric data, government-issued identity documents, social security numbers, and counterparty transaction data—and the purposes for which that information is used, shared, and retained. Coinbase retains personal information as long as needed to provide Services, satisfy legal obligations, or protect its or others' interests, with no fixed deletion timeline. The document grants Coinbase authority to use automated decision-making for regulatory and contractual obligations related to safety, security, and integrity, and to transfer personal information in the event of a merger, acquisition, bankruptcy, or similar change of control. Users hold a qualified right to request erasure subject to applicable law, but have no right to opt out of critical legal or security communications. Unresolved privacy complaints under the Data Privacy Frameworks may be subject to binding arbitration through ICDR-AAA.

What this means for you

As an individual user, your most sensitive personal information—including biometric data generated from photos or videos, government-issued identity documents, and social security numbers—is collected as part of identity verification and may be retained beyond the end of your account relationship if legal obligations or protective interests require it. Your conversion data, including your IP address, is shared with named third-party advertisers such as Meta and AppLovin. If Coinbase undergoes an acquisition, merger, or bankruptcy, your personal information may transfer to a different entity. Coinbase will close your account if it is unable to process your personal information for its stated purposes. You can contact Coinbase to submit a personal information erasure request, though applicable law may limit whether that request must be honored.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

8 important changes detected

9 versions captured · Last updated: May 2026

What changed Coinbase updated its privacy policy on May 28, 2026 with minor corrections to language and references. The changes include fixing quotation mark formatting around 'European Personal Data', adjusting section heading formatting for Data Privacy Framework references, correcting an internal policy reference from Section 3 to Section 34, and updating a URL for the Data Privacy Framework complaint process from https://go.adr.org/dpf_irm.html to https://feature.adr.org/dpf_irm. These are primarily editorial and administrative corrections with no material change to substantive privacy commitments or operational procedures.
Why this matters The updated policy contains minor editorial corrections that do not materially change Coinbase's privacy commitments or data handling practices. The substantive provisions regarding Data Privacy Framework compliance, personal data transfers, and dispute resolution procedures remain unchanged. The corrected internal reference (Section 34 instead of Section 3) and updated complaint process URL ensure users can access the proper dispute resolution mechanism.
View full change record →
What changed Coinbase made five minor editorial corrections to its Privacy Policy on May 1, 2026. The changes include fixing a spelling inconsistency (changing 'endeavour' to 'endeavor'), adding missing spaces before periods in three email addresses, and correcting a typo ('reside' to 'reside') in the Argentina data protection authority section. These are formatting and spelling corrections with no material impact on the substantive rights, obligations, or procedures described in the policy.
Why this matters This change has no material impact on consumer rights or data governance practices. The updated policy corrects spelling and formatting errors in contact information for data protection requests and complaint procedures. The substance of how users can contact Coinbase or relevant regulatory authorities remains unchanged. No action is required on the part of consumers.
View full change record →

April 29, 2026 low

Coinbase updated internal section references in its Privacy Policy on April 29, 2026 by renumbering sections throughout the document. The policy previously referenced Section 7, 11, 4, and 9 for …

View change record →
April 19, 2026 low

Coinbase's privacy policy was updated on April 19, 2026, with a minor modification to a sentence describing how the platform uses customer data to provide access to Verified Pools, a …

View change record →
April 5, 2026 low

Coinbase modified a single sentence in their Privacy Policy on April 5, 2026, regarding the Verified Pools blockchain protocol. The change involved adding a single space character in the description …

View change record →
April 3, 2026 low

Coinbase removed a single sentence from its privacy policy that previously provided a link to access the prior version of the policy. The updated policy no longer includes explicit language …

View change record →
April 2, 2026 low

Coinbase removed a single sentence from its privacy policy that previously stated 'Previous Privacy Policy can be found here.' This removal eliminates the direct link or reference to accessing prior …

View change record →
March 6, 2026 low

Coinbase updated its Privacy Policy on March 6, 2026, making primarily technical and formatting corrections. The changes include correcting section reference numbers throughout the policy (for example, changing references from …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

107 provisions
12 featured
16 clause types
29 high severity
AI / Automated Decision-Making 1 1 high
Acceptable Use Restrictions 1 1 high
Disclosure and Transparency Requirements 1
Stay ahead of the changes

Monitoring

Coinbase has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Account closure and data deletion for underage users and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Consumer Rights · April 14, 2026
Coinbase Requires Mandatory Arbitration. You Have 30 Days to Opt Out.

Coinbase's User Agreement includes a mandatory arbitration clause that most users may not have reviewed. Here is what the clause states and…

Archival ProvenanceSource & Archival Record
Last Captured May 28, 2026 00:04 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000048
Version ID CA-V-003052
SHA-256 (extracted text; extractor version not recorded, so this hash may not reproduce today) 378e242ef7ef7357a0930156715c137fefbd818ce139f51127d06e5ba9cd315b
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans