Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that account deletion requests may not result in complete data removal where trust, safety, fraud, open insurance claims, or open legal claims apply. Data retained post-deletion is described as being stored in a manner designed to limit its use to the stated retention purpose.
This analysis describes what Lyft's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that account deletion does not guarantee full erasure of personal information, with retention permitted for safety, fraud, insurance, and legal claim purposes. The absence of a stated maximum retention period for these categories creates open-ended post-deletion data retention that may interact with erasure rights under applicable privacy law.
Interpretive note: The duration of post-deletion retention for trust, safety, fraud, and open claim purposes is not quantified in the document, creating ambiguity about the practical scope of data retention following an account deletion request.
Under these terms, submitting an account deletion request does not result in removal of data retained for insurance, legal, safety, or fraud-related purposes, and the policy does not specify a maximum duration for such retention. The agreement states that retained data is stored in ways designed to prevent its use for other purposes, though the mechanism for enforcing that limitation is not described.
Cross-platform context
See how other platforms handle Post-Account-Deletion Data Retention Carve-Outs and similar clauses.
Compare across platforms →Monitoring
Lyft has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"If you request account deletion, we will delete your information as set forth in the "Deleting Your Account" section below. In some cases, we will be unable to delete your account, such as if there is an issue with your account related to trust, safety, or fraud. When we delete your account, we may retain certain information for legitimate business purposes or to comply with legal or regulatory obligations. For example, we may retain your information to resolve open insurance claims, or we may be obligated to retain your information as part of an open legal claim. When we retain such data, we do so in ways designed to prevent its use for other purposes.Excerpt from Lyft's Privacy Policy
1) REGULATORY LANDSCAPE: Post-deletion retention carve-outs engage erasure rights under the CCPA, state comprehensive privacy statutes, and UK data protection law. These frameworks generally permit retention for legal compliance purposes but require that the retention be limited to what is necessary and that the data not be used for other purposes. The CCPA and similar statutes also require that consumers be informed when their deletion request cannot be fully honored. 2) GOVERNANCE EXPOSURE: Medium. The carve-outs for insurance claims, legal claims, safety, and fraud are commonly observed in privacy policies and are generally recognized as lawful bases for retention. However, the absence of quantified maximum retention periods for these categories and the general reference to trust and safety as a basis for declining deletion creates ambiguity about the practical scope of the carve-out. 3) JURISDICTION FLAGS: California requires that consumers be notified when a deletion request cannot be fully honored and that the basis for denial be disclosed. Colorado and Connecticut impose similar requirements. UK data protection law provides a right to erasure subject to defined exceptions including legal claims and public interest. 4) CONTRACT AND VENDOR IMPLICATIONS: Vendors and service providers retaining personal data post-account-deletion on Lyft's behalf require data processing agreements that confirm retention is limited to the stated purposes and that data is isolated from active processing systems. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the process for notifying users of partial deletion denials meets applicable state requirements, whether the trust, safety, and fraud carve-out is documented with defined criteria and review timelines, and whether post-deletion data stores are technically isolated from operational processing systems as the policy asserts.
This provision establishes that account deletion does not guarantee full erasure of personal information, with retention permitted for safety, fraud, insurance, and legal claim purposes. The absence of a stated maximum retention period for these categories creates open-ended post-deletion data retention that may interact with erasure rights under applicable privacy law.
Under these terms, submitting an account deletion request does not result in removal of data retained for insurance, legal, safety, or fraud-related purposes, and the policy does not specify a maximum duration for such retention. The agreement states that retained data is stored in ways designed to prevent its use for other purposes, though the mechanism for enforcing that limitation …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Lyft.