125 Total
27 High severity
79 Medium severity
19 Low severity

Key Facts

When must GOAT's biometric identifier be destroyed?
GOAT's biometric identifier is generated and held by Persona until GOAT instructs Persona that it is no longer needed for the described purposes and must be destroyed.
To what jurisdictions may a user's personal information be transferred?
By providing personal information to GOAT, a user acknowledges and agrees that their personal information may be transferred to other jurisdictions for processing and storage, including servers in Canada and the United States, where data protection laws may be less stringent.
Under what circumstances may EU, UK, and Swiss individuals invoke binding arbitration regarding complaints about GOAT's collection and use of personal data?
EU, UK, and Swiss individuals may, under certain circumstances, invoke binding arbitration regarding complaints about GOAT's collection and use of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
What has GOAT certified to the U.S. Department of Commerce?
GOAT has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles with regard to the processing of personal data received from the European Union.
Does GOAT use, disclose, or retain biometric information for any commercial purpose other than those described in the relevant paragraph?
GOAT does not use, disclose, or retain biometric information for any commercial purpose other than those described in the relevant paragraph.
May GOAT share personal information with advertising networks?
GOAT may share personal information with advertising networks, or permit those partners to collect information directly from users on GOAT's sites, to facilitate online advertising including targeted ads through search engines and social network advertising providers.
Does GOAT share SMS consent and related phone numbers with third parties?
GOAT does not share SMS consent and related phone numbers with third parties, except with its shipping and logistics partners as necessary to send delivery-related text messages, and except as otherwise disclosed in the Privacy Policy.
With whom does GOAT share SMS consent and related phone numbers?
GOAT does not share SMS consent and related phone numbers with third parties, except with its shipping and logistics partners as necessary to send delivery-related text messages, and except as otherwise disclosed in the Privacy Policy.
Are GOAT's Services directed to children under the age of 16?
GOAT's Services are not directed to children under the age of 16, or under 18 for individuals located in China, and GOAT does not intend to or knowingly collect or solicit personal information from those children.
Does GOAT knowingly collect or solicit personal information from children under the age of 16, or under 18 for individuals located in China?
GOAT's Services are not directed to children under the age of 16, or under 18 for individuals located in China, and GOAT does not intend to or knowingly collect or solicit personal information from those children.
Stay ahead of the changes
Track GOAT and get the diff the day its terms change.
Summary

This document explains what personal information GOAT collects, how it uses and shares that information, and what rights you have over it. GOAT may share your information with advertising networks for targeted ads and with shipping partners for delivery communications, and your biometric data is held by a third-party service until GOAT tells that service to delete it. You have the right to tell GOAT not to sell your personal information or share it for cross-context behavioral advertising.

Analysis

This privacy policy establishes GOAT's data collection, usage, sharing, retention, and user rights framework. GOAT may share personal information with advertising networks—either directly or by permitting those networks to collect it from GOAT's sites—and shares contact information such as phone numbers with shipping and delivery partners. Biometric identifiers are held by a third-party processor (Persona) and persist until GOAT actively instructs Persona to destroy them; biometric information is restricted to the described purposes and not used for any other commercial purpose. Users retain the right to direct GOAT not to sell or share their personal information for cross-context behavioral advertising, and not to apply automated decision-making or profiling for certain purposes. GOAT has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles for personal data received from the European Union, and the policy treats the act of providing personal information as acknowledgment of and agreement to potential transfer to Canada or the United States.

What this means for you

As a GOAT user, your personal information may be shared with advertising networks—including by allowing those networks to collect it directly from GOAT's sites—and your phone number is shared with shipping and delivery partners who may contact you about deliveries. If you are located in the EU, UK, or Switzerland, you may invoke binding arbitration over complaints about GOAT's collection and use of your personal data under the applicable Data Privacy Frameworks. Your biometric identifier is retained by a third-party processor until GOAT instructs that processor to destroy it. You can direct GOAT not to sell your personal information or share it for cross-context behavioral advertising, and you can direct GOAT not to apply automated decision-making or profiling for certain purposes.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

1 important change detected

2 versions captured · Last updated: May 2026

What changed GOAT updated its privacy policy to clarify how it shares your phone number and other contact information with shipping partners for delivery notifications. The policy now explicitly states that shipping carriers may send you text messages with tracking updates, delivery scheduling, and confirmations directly on GOAT's behalf. The update also specifies that message rates may apply, message frequency varies based on order activity, and you can opt out of delivery texts without affecting security-related messages like authentication codes.
Why this matters The updated policy establishes clearer disclosure of how GOAT handles phone number sharing with shipping partners. Under the revised terms, your phone number and order information may be shared with shipping carriers so they can send you delivery-related text messages, including tracking updates, delivery scheduling, and confirmations. The policy now specifies that message and data rates may apply and that message frequency varies based on your order activity. You can opt out of delivery-related text messages by replying STOP or clicking unsubscribe links, though this does not affect security-related messages such as multifactor authentication codes.
View full change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

125 provisions
12 featured
21 clause types
27 high severity
Data Sharing 21 12 high
Show all 21 data sharing provisions
Privacy Rights 33 2 high
Show all 33 privacy rights provisions
AI / Automated Decision-Making 1 1 high
Indemnification 1 1 high
Stay ahead of the changes

Monitoring

GOAT has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Biometric identifier held by Persona until destruction instructed and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 9, 2026 03:05 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000736
Version ID CA-V-002374
SHA-256 0787144e6e94c8f94e25d111a32de5d33f857ac588bc8c3d3e954bccbcd71826
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans