Provision record
Gusto · Gusto Privacy Policy · View original document ↗

Third-Party Data Sharing with Service Providers and Partners

Medium severity Medium confidence Explicit document language Common · 288 of 352 platforms
Stay ahead of the changes
Track Gusto and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Gusto shares your personal data including payroll and financial information with external companies that help deliver its services, as well as business partners who may offer additional products.

This analysis describes what Gusto's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Your most sensitive data, including payroll figures and bank account details, flows to multiple third parties, expanding the number of entities that hold and could potentially expose your information.

Interpretive note: The distinction between service provider sharing and business partner sharing for promotional purposes has different legal implications under CPRA; the policy does not clearly delineate the boundaries between these categories for all data flows.

Recent Activity

This document changed recently

Medium Aug 29, 2026

The updated policy explicitly discloses that Gusto sells or shares personal information (defined under state privacy laws) with third parties including business, advertising, and technology partners. The company describes 'sale' as providing information in exchange for valuable consideration, and 'share' as providing information for cross-context behavioral advertising. This disclosure formalizes practices that may have been permitted under previous language but were not explicitly described. You can opt out of sales or sharing of personal information through the Cookies, Analytics, and Other Tracking Technologies section.

View change record →
Medium Jun 1, 2026

The updated Privacy Policy now explicitly states it covers retirement account management (401k, SEP IRA, IRA accounts) and adds Stripe alongside Plaid as a third-party service provider that collects financial institution data. The policy restructures how it describes Gusto's role in different contexts: when Gusto acts as a service provider processing payroll or other data on behalf of employers, when it acts as an employer itself, or when it operates as a co-employer under a professional organization (PEO) arrangement, with separate privacy notices applying in each case. The policy introduces a new commitment that de-identified data will not be re-identified except to verify compliance with applicable law. If you connect a bank account through Stripe, that data will be treated under Stripe's Privacy Policy, which you should review separately.

View change record →

Clause Stability Stable

0
Changes
5
Months Monitored
May 7, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 4430 other provisions on other platforms.

Change history

modified May 14, 2026

Severity downgraded from high to medium; previous version had empty excerpt while current version specifies categories of third parties (vendors, service providers, business partners, financial institutions) and their purposes.

View full change record →

Consumer impact (what this means for users)

Your payroll, tax, and financial account data is shared with third-party financial service providers and business partners by design, meaning data security risks are not limited to Gusto itself but extend across its vendor and partner network.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit privacy.gusto.com to submit an opt-out of sale or sharing request or a deletion request if you wish to limit how your data is shared with Gusto's business partners.

How other platforms handle this

Skillshare Medium

We share Personal Data with vendors, service providers, and agents who work on our behalf and provide us with services related to the purposes described in this Privacy Policy or our Terms of Service.

Adobe Medium

We will disclose personal information to companies that help us run our business to detect, prevent, or otherwise address fraud, deception, illegal activity, misuse of Adobe Services and Software, and security or technical issues.

Oura Medium

We also require these service providers to protect your personal information to at least the same standards that we do.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
We may share your personal information with third-party vendors and service providers that perform services on our behalf, such as payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance. We may share your information with our business partners to offer you certain products, services, or promotions. We disclose personal information to third-party financial service providers to facilitate payroll, tax, and other financial services.

Excerpt from Gusto's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Third-party data sharing with financial service providers engages GLBA and its Safeguards Rule, which requires financial institutions to oversee service provider data security.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • Consumer Financial Protection Bureau (cfpb)
    Regulates consumer financial products and services. Can investigate companies for unfair, deceptive, or abusive financial practices including improper fees, billing errors, and data misuse.
    Who can file: Anyone who has used a consumer financial product or service in the US
    What you need: Account number or details, dates of transactions or events, description of the issue, and any supporting documents
    What to expect: The company must respond within 15 days. The CFPB forwards your complaint and may use it in enforcement actions. Individual compensation is possible in some cases.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Gusto Privacy Policy
Entity
Gusto
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-005696
Document ID
CA-D-00294
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c4d8f17389d7d8490a863657e4b23ec13d3e6ba6188da2fae2a3bc7f510d2148
Analysis generated
May 10, 2026 11:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Gusto
Document: Gusto Privacy Policy
Record ID: CA-P-005696
Captured: 2026-05-10 11:04:56 UTC
SHA-256: c4d8f17389d7d849…
URL: https://conductatlas.com/platform/gusto/gusto-privacy-policy/provision/CA-P-005696/third-party-data-sharing-with-service-providers-and-partners/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Gusto's Third-Party Data Sharing with Service Providers and Partners clause do?

Your most sensitive data, including payroll figures and bank account details, flows to multiple third parties, expanding the number of entities that hold and could potentially expose your information.

How does this clause affect you?

Your payroll, tax, and financial account data is shared with third-party financial service providers and business partners by design, meaning data security risks are not limited to Gusto itself but extend across its vendor and partner network.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.

Is ConductAtlas affiliated with Gusto?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Gusto.