The policy states that after removing identifiers including name, phone number, and email address, Lime may share individual trip records and trip location history with third parties including universities for research and business purposes.
This analysis describes what Lime's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes sharing of granular location and trip data with third parties after partial de-identification. The de-identification process described removes named identifiers but retains individual trip records and location journey histories, which regulatory and academic literature indicates can present residual re-identification risk. The scope of 'business or other purposes' is not defined.
Interpretive note: Whether the de-identification process described meets GDPR anonymization standards or CCPA de-identification requirements is a legal and technical determination that cannot be made from the document text alone.
Under this clause, Lime may share individual trip records and location history data with third parties after removing name, phone, and email, but the policy does not specify additional technical de-identification measures applied to the granular location and journey records that are shared.
Cross-platform context
See how other platforms handle Trip Location History Sharing with Research Partners and similar clauses.
Compare across platforms →"After removing certain identifiers, such as your name, phone, and e-mail address (where provided), and combining the resulting information with similar information from other users, Lime may share your information, including individual trip records and trip location (journey) history, with third parties for research, business or other purposes.Excerpt from Lime's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR and UK GDPR anonymization standards, under which data is only considered anonymous if re-identification is not reasonably possible; removing name, phone, and email while retaining individual trip records …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes sharing of granular location and trip data with third parties after partial de-identification. The de-identification process described removes named identifiers but retains individual trip records and location journey histories, which regulatory and academic literature indicates can present residual re-identification risk. The scope of 'business or other purposes' is not defined.
Under this clause, Lime may share individual trip records and location history data with third parties after removing name, phone, and email, but the policy does not specify additional technical de-identification measures applied to the granular location and journey records that are shared.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Lime.