The policy authorizes transfer of User Personal Information to a successor entity in a merger, sale, or acquisition, with advance notice via website or email and a commitment that the receiving organization will honor existing privacy commitments.
This analysis describes what Fly.io's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that User Personal Information may transfer to a new organizational owner, with the commitment that privacy policy obligations transfer to the acquiring entity. The enforceability of that commitment against a successor depends on the terms of the transaction and applicable law, which the document does not address.
The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.
View change record →Under this clause, User Personal Information may be transferred to an acquiring entity in a change of ownership event, with Fly.io committing to provide advance notice and require the acquirer to honor existing privacy commitments. The mechanism for enforcing the acquirer's compliance with those commitments is not specified.
Cross-platform context
See how other platforms handle Merger and Acquisition Data Transfer and similar clauses.
Compare across platforms →"We may share User Personal Information if we are involved in a merger, sale, or acquisition. If any such change of ownership happens, we will ensure that it is under terms that preserve the confidentiality of User Personal Information, and we will notify you on our website or by email before any transfer of your User Personal Information. The organization receiving any User Personal Information will have to honor any promises we have made in our Privacy Statement or in our Terms of Service.Excerpt from Fly.io's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR requirements for lawful data transfer in corporate transactions, FTC guidance on data as an asset in acquisitions, and CCPA provisions regarding transfers of personal information in business transactions.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that User Personal Information may transfer to a new organizational owner, with the commitment that privacy policy obligations transfer to the acquiring entity. The enforceability of that commitment against a successor depends on the terms of the transaction and applicable law, which the document does not address.
Under this clause, User Personal Information may be transferred to an acquiring entity in a change of ownership event, with Fly.io committing to provide advance notice and require the acquirer to honor existing privacy commitments. The mechanism for enforcing the acquirer's compliance with those commitments is not specified.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Fly.io.