8 Total
0 High severity
4 Medium severity
4 Low severity
Summary

This document establishes Craigslist's practices regarding collection, use, and storage of personal information including name, email, phone number, location, and device data. The policy specifies that personal data is not sold or shared for advertising purposes, but authorizes transfer and storage of user data on United States-based servers regardless of user location. The document states that data security measures are provided on a good faith basis without guarantee of complete protection.

Technical / Legal Breakdown

This document is Craigslist's privacy policy (updated May 29, 2024) governing data collection, use, storage, and disclosure across its websites, mobile applications, and related services. The policy explicitly states that Craigslist does not sell user data to third parties, does not share data for marketing purposes, and does not run advertising beyond user-posted classifieds; data is disclosed externally only to payment processors, phone verification service providers, fraud-prevention service providers, and in response to legal process or corporate transactions. Notably, the policy does not respond to 'Do Not Track' signals, makes no guarantee of data security (stating only 'good faith efforts'), and the international data transfer clause operates as a consent-by-use mechanism, which may engage evaluation under GDPR adequacy and transfer requirements for users in the EU and EEA. The policy acknowledges California Consumer Privacy Act rights for California residents, including rights to know, delete, and non-discrimination, with submission mechanisms at a dedicated URL and email address; it also provides a minor-user content removal mechanism under California law. Compliance teams should note the absence of explicit references to GDPR consent bases, data processing agreements, or a formal data retention schedule, which may create exposure for operations affecting EU or UK users.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 4 provisions
Low — 4 provisions

Monitoring

Craigslist has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle International Data Transfer — Consent by Access and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 18, 2026 07:55 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000288
Version ID CA-V-000615
SHA-256 8baa4856fec8918cb91d5602a07f9aea799b51b2438ba15871b5b80dff8ecde7
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans