8 Total
1 High severity
7 Medium severity
0 Low severity
Summary

This document establishes GOAT's data collection and processing practices for users of its sneaker and apparel marketplace platform. The policy authorizes GOAT to collect personal information including name, address, payment details, device identifiers, geolocation data, and behavioral inferences, and permits sharing this information with third-party business partners for their marketing and advertising purposes. The policy establishes data subject rights for California residents and EU users, including mechanisms to request access to, deletion of, or opt-out from certain data processing activities.

Technical / Legal Breakdown

This document is GOAT's Privacy Policy, governing the collection, use, and sharing of personal information across GOAT's global platform for sneakers, apparel, and accessories, with stated applicability to users in the US, EU, UK, Canada, Australia, and other jurisdictions. The policy states that GOAT collects a broad range of personal data including identifiers, commercial transaction data, device and usage information, geolocation data, payment information, and inferences drawn from user behavior, and the terms authorize use of this data for purposes including marketing, advertising, analytics, and sharing with third-party business partners and service providers. The policy's authorization to share data with 'business partners' for their own marketing purposes, and to derive behavioral inferences from user activity, represents a scope of secondary data use that consumers may not anticipate from a retail platform, though applicable law in various jurisdictions may constrain how broadly these authorizations can be exercised in practice. The policy engages GDPR and UK GDPR for EU and UK residents, the California Consumer Privacy Act and California Privacy Rights Act for California residents, and general FTC Act consumer protection standards; rights afforded vary materially by jurisdiction, with EU and California users receiving more substantive access, deletion, and opt-out entitlements than users in other regions. Compliance teams should note the policy's simultaneous operation across multiple regulatory regimes, the inclusion of targeted advertising opt-out mechanisms, and the broad framing of 'business partners' as data recipients, each of which warrants careful mapping against applicable legal obligations.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

1 important change detected

2 versions captured · Last updated: May 2026

What changed GOAT updated its privacy policy to clarify how it shares your phone number and other contact information with shipping partners for delivery notifications. The policy now explicitly states that shipping carriers may send you text messages with tracking updates, delivery scheduling, and confirmations directly on GOAT's behalf. The update also specifies that message rates may apply, message frequency varies based on order activity, and you can opt out of delivery texts without affecting security-related messages like authentication codes.
Why this matters The updated policy establishes clearer disclosure of how GOAT handles phone number sharing with shipping partners. Under the revised terms, your phone number and order information may be shared with shipping carriers so they can send you delivery-related text messages, including tracking updates, delivery scheduling, and confirmations. The policy now specifies that message and data rates may apply and that message frequency varies based on your order activity. You can opt out of delivery-related text messages by replying STOP or clicking unsubscribe links, though this does not affect security-related messages such as multifactor authentication codes.
View full change record →
High — 1 provision
Medium — 7 provisions

Monitoring

GOAT has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Third-Party Advertising Pixel & Tracking Technology Deployment and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 9, 2026 03:05 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000736
Version ID CA-V-002374
SHA-256 0787144e6e94c8f94e25d111a32de5d33f857ac588bc8c3d3e954bccbcd71826
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans