Gusto's policy indicates it may collect biometric information, which could include fingerprints or facial recognition data, as part of its HR or time-tracking services.
This analysis describes what Gusto's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Biometric data collection has distinct regulatory requirements under laws like BIPA (Biometric Information Privacy Act) in certain jurisdictions. The provision's operational significance lies in establishing the lawful basis and scope for processing this category of sensitive personal information within Gusto's service delivery model.
The updated policy explicitly discloses that Gusto sells or shares personal information (defined under state privacy laws) with third parties including business, advertising, and technology partners. The company describes 'sale' as providing information in exchange for valuable consideration, and 'share' as providing information for cross-context behavioral advertising. This disclosure formalizes practices that may have been permitted under previous language but were not explicitly described. You can opt out of sales or sharing of personal information through the Cookies, Analytics, and Other Tracking Technologies section.
View change record →The updated Privacy Policy now explicitly states it covers retirement account management (401k, SEP IRA, IRA accounts) and adds Stripe alongside Plaid as a third-party service provider that collects financial institution data. The policy restructures how it describes Gusto's role in different contexts: when Gusto acts as a service provider processing payroll or other data on behalf of employers, when it acts as an employer itself, or when it operates as a co-employer under a professional organization (PEO) arrangement, with separate privacy notices applying in each case. The policy introduces a new commitment that de-identified data will not be re-identified except to verify compliance with applicable law. If you connect a bank account through Stripe, that data will be treated under Stripe's Privacy Policy, which you should review separately.
View change record →Removal of this high-severity provision eliminates transparency about biometric data practices, potentially indicating either that biometric collection has been discontinued or that disclosure obligations have been de-emphasized.
View full change record →The collection of biometric data by Gusto creates heightened privacy risks as this data is permanent and irrevocable. Users in states with biometric privacy laws such as Illinois (BIPA) should be aware of their specific rights and consent requirements.
How other platforms handle this
You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.
NIM container releases that collect data, collect it for the following purposes: (a) to properly configure and optimize products for use with Software; and (b) to improve NVIDIA products and services.
Some of our ad partners may also enable us to collect similar data directly from their website or app by integrating our or our affiliates' advertising technology.
Biometric data collection implicates Illinois BIPA, Texas CUBI, Washington's biometric privacy law, and CCPA/CPRA's sensitive personal information category.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Biometric data collection has distinct regulatory requirements under laws like BIPA (Biometric Information Privacy Act) in certain jurisdictions. The provision's operational significance lies in establishing the lawful basis and scope for processing this category of sensitive personal information within Gusto's service delivery model.
The collection of biometric data by Gusto creates heightened privacy risks as this data is permanent and irrevocable. Users in states with biometric privacy laws such as Illinois (BIPA) should be aware of their specific rights and consent requirements.
ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Gusto.