Grindr · Grindr Privacy Policy · View original document ↗

Post-Opt-Out Sensitive Data Processing Carve-Out

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Grindr changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Grindr recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Grindr Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that withdrawing consent applies only to future processing and that following an opt-out, sensitive or special-category data may continue to be processed where permitted under applicable law.

This analysis describes what Grindr's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a carve-out permitting continued processing of sensitive data after user opt-out under legal bases other than consent; the scope of those alternative legal bases is not enumerated in this clause, creating compliance questions regarding which processing purposes may continue without consent.

Interpretive note: The provision does not enumerate the specific legal bases that would support continued processing of sensitive data after opt-out, creating ambiguity about the scope of processing that may lawfully continue in each jurisdiction.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, opting out of certain sensitive data uses does not guarantee cessation of all processing; the agreement states that sensitive data may continue to be processed where permitted under applicable law, and the specific legal bases that would support such continued processing are not enumerated in this provision.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a deletion request to privacy@grindr.com or via the in-app request mechanism. Note that the policy states certain data may be retained for safety, security, fraud prevention, and legal compliance purposes even following a deletion request.

Cross-platform context

See how other platforms handle Post-Opt-Out Sensitive Data Processing Carve-Out and similar clauses.

Compare across platforms →

Monitoring

Grindr has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Where we process personal information based on your consent, you may withdraw that consent at any time. Withdrawing your consent will only apply to future processing activities and will not affect the lawfulness of any processing carried out before you withdrew your consent. For example, you may be able to withdraw your consent or opt out of certain uses of your 'sensitive' or 'special category' data by going to your in-app Settings and then tapping Privacy Settings. Note that if you opt out, your data may continue to be processed where permitted under applicable law.

Excerpt from Grindr's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 7(3) (right to withdraw consent) and Article 9 (special-category data), which require that withdrawal of consent results in cessation of consent-based processing. Where Grindr relies on alternative legal bases (such as legitimate interests or legal obligations) to continue processing after opt-out, those bases must themselves be documented and valid under Article 9(2). Relevant enforcement authorities include EU member state DPAs and the UK ICO. The phrase 'where permitted under applicable law' is not defined in the provision, which may create tension with the specificity requirements of GDPR transparency obligations. 2. GOVERNANCE EXPOSURE: High. The absence of enumerated alternative legal bases for post-opt-out processing of special-category data creates documented uncertainty about the scope of continued processing following user opt-out, which may not align with GDPR transparency and data minimization principles. This language applies to health data (HIV status, vaccination status), racial/ethnic origin, and other sensitive fields. 3. JURISDICTION FLAGS: EU/EEA and UK create heightened exposure given GDPR Article 9 requirements. California CPRA imposes restrictions on the processing of sensitive personal information and requires opt-out mechanisms; the adequacy of the carve-out language under CPRA should be assessed. Washington My Health MY Data Act may impose stricter limitations on continued processing of consumer health data after opt-out. 4. CONTRACT AND VENDOR IMPLICATIONS: If sensitive data continues to flow to advertising or service provider partners following user opt-out under alternative legal bases, those partner contracts must reflect the applicable legal basis and processing restrictions. Procurement teams should verify that vendor agreements address post-opt-out processing obligations. 5. COMPLIANCE CONSIDERATIONS: Legal teams should document and map each legal basis that supports continued processing of special-category data following consent withdrawal, and ensure those bases are disclosed with sufficient specificity to meet GDPR transparency requirements. A consent mechanism audit should assess whether the current Ketch CMP implementation accurately reflects the scope of processing that continues after opt-out. Regulatory notifications or DPA consultations may be warranted where processing of sensitive data under legitimate interests is relied upon as an alternative to consent.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC may evaluate whether post-opt-out continued processing of sensitive data without clearly disclosed legal bases constitutes an unfair or deceptive practice under Section 5 of the FTC Act.
    File a complaint →
  • State AG
    California, Washington, and Nevada attorneys general have enforcement authority over sensitive health data processing and opt-out mechanisms under CPRA, the My Health MY Data Act, and Nevada's consumer health data statute.
    File a complaint →

Provision details

Document information
Document
Grindr Privacy Policy
Entity
Grindr
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015012
Document ID
CA-D-00270
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d975ff63d08e3c4b736841b3b0bc5d768ca9e5f4b20e241c55c4c227fb46ef8c
Analysis generated
July 9, 2026 06:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Grindr
Document: Grindr Privacy Policy
Record ID: CA-P-015012
Captured: 2026-07-09 06:55:48 UTC
SHA-256: d975ff63d08e3c4b…
URL: https://conductatlas.com/platform/grindr/grindr-privacy-policy/provision/CA-P-015012/post-opt-out-sensitive-data-processing-carve-out/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Grindr's Post-Opt-Out Sensitive Data Processing Carve-Out clause do?

This provision establishes a carve-out permitting continued processing of sensitive data after user opt-out under legal bases other than consent; the scope of those alternative legal bases is not enumerated in this clause, creating compliance questions regarding which processing purposes may continue without consent.

How does this clause affect you?

Under this clause, opting out of certain sensitive data uses does not guarantee cessation of all processing; the agreement states that sensitive data may continue to be processed where permitted under applicable law, and the specific legal bases that would support such continued processing are not enumerated in this provision.

Is ConductAtlas affiliated with Grindr?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grindr.