58 Total
22 High severity
30 Medium severity
6 Low severity

Key Facts

Does Mercury rely on AI alone to make decisions that could have legal consequences, financial implications, or otherwise materially affect users' rights or access to services?
Mercury states that it does not rely on AI alone to make decisions that could have legal consequences, financial implications, or otherwise materially affect users' rights or access to services, and that such decisions always involve appropriate human oversight.
What involves appropriate human oversight when decisions could have legal consequences, financial implications, or otherwise materially affect users' rights or access to services?
Mercury states that it does not rely on AI alone to make decisions that could have legal consequences, financial implications, or otherwise materially affect users' rights or access to services, and that such decisions always involve appropriate human oversight.
Under certain U.S. privacy laws, what may Mercury's use of advertising cookies and similar technologies be considered even though Mercury does not exchange user information for money?
Mercury states that under certain U.S. privacy laws, its use of advertising cookies and similar technologies may be considered 'sharing' or a 'sale' of Personal Information even though Mercury does not exchange user information for money.
What biometric information does Mercury collect?
Mercury collects biometric information, including voiceprint, facial scan, and biometrics extracted from a photograph or image, for identity purposes.
For what purposes does Mercury collect biometric information?
Mercury collects biometric information, including voiceprint, facial scan, and biometrics extracted from a photograph or image, for identity purposes.
Who is responsible for ensuring a lawful basis to provide Personal Information to Mercury?
Mercury requires that the business customer is responsible for ensuring it has a lawful basis to provide Personal Information to Mercury.
To whom does Mercury disclose Personal Information as part of any reorganization, merger, sale, joint venture, assignment, or transfer?
Mercury discloses Personal Information to parties involved in a corporate transaction, such as a potential or actual acquirer, successor, or assignee, as part of any reorganization, merger, sale, joint venture, assignment, or transfer.
In what corporate transactions does Mercury disclose Personal Information?
Mercury discloses Personal Information to parties involved in a corporate transaction, such as a potential or actual acquirer, successor, or assignee, as part of any reorganization, merger, sale, joint venture, assignment, or transfer.
What does Mercury rely on for transfers of Personal Information from the European Economic Area or United Kingdom?
Mercury relies on approved contractual protections, such as Standard Contractual Clauses, and additional technical and organizational safeguards for transfers of Personal Information from the European Economic Area or United Kingdom.
What safeguards does Mercury rely on for transfers of Personal Information from the European Economic Area or United Kingdom?
Mercury relies on approved contractual protections, such as Standard Contractual Clauses, and additional technical and organizational safeguards for transfers of Personal Information from the European Economic Area or United Kingdom.
Stay ahead of the changes
Track Mercury and get the diff the day its terms change.
Summary

Mercury's Privacy Policy explains what personal data Mercury collects—including biometric data like facial scans and voiceprints—how it is used, and with whom it may be shared, including in corporate transactions such as mergers. Mercury does not sell your Personal Information for money, but its use of advertising cookies may legally count as a 'sale' or 'sharing' under certain U.S. privacy laws, giving you the right to opt out by clicking 'Your Privacy Choices' or enabling GPC. Mercury also states it never uses AI alone for decisions that could materially affect your legal or financial standing.

Analysis

This Privacy Policy establishes Mercury's practices for collecting, using, retaining, and sharing Personal Information, including sensitive categories such as biometric data. It sets a human-oversight requirement for consequential AI-assisted decisions and limits Mercury AI output from serving as a substitute for professional legal, financial, or tax advice. Data retention is governed by a necessity standard subject to extension under applicable financial-sector regulatory obligations. Cross-border transfers from the EEA and UK are covered by Standard Contractual Clauses and additional technical and organizational safeguards, and business customers bear responsibility for ensuring a lawful basis before providing Personal Information to Mercury.

What this means for you

Mercury collects highly sensitive personal data, including biometrics, and may share Personal Information with potential or actual acquirers in corporate transactions. Its use of advertising cookies may qualify as a 'sale' or 'sharing' of your Personal Information under applicable U.S. privacy law. If that right applies to you, you can exercise it by clicking the 'Your Privacy Choices' link on Mercury's platform or by enabling the Global Privacy Control (GPC) in your browser. Mercury also commits that any AI-assisted decision with legal or financial consequences for you will always include appropriate human oversight.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

9 versions captured · Last updated: August 2026

What changed Mercury's privacy policy was updated to expand the types of personal information the company collects and processes, particularly for business customers and their connected individuals. New language clarifies that Mercury may collect data directly from payment recipients, contractors, and other third parties at a business's direction, and adds specific examples of payment and payroll processing purposes. The policy also modifies SMS messaging consent terms to distinguish between transactional and marketing messages, and removes 'affiliates' from a previous restriction on sharing mobile opt-in data.
Why this matters The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.
View full change record →
What changed Mercury's privacy policy was updated on August 22, 2026 to add 'Opens in new tab' annotations to three external links: the Google Analytics opt-out tool, the Network Advertising Initiative, and the Digital Advertising Alliance. The policy also made minor punctuation corrections. These changes are purely procedural and do not alter the substance of Mercury's privacy practices, data collection practices, or user opt-out rights.
Why this matters This change does not materially affect how Mercury collects, uses, or protects your personal information. The policy continues to permit the same opt-out mechanisms for advertising tracking: Mercury's cookie preference tools, browser settings, device-level privacy settings, and third-party industry programs. The added 'Opens in new tab' labels are a formatting change that clarifies how external links will open in your browser, with no impact on your privacy rights or choices.
View full change record →

August 19, 2026 low

Mercury's privacy policy was updated on August 19, 2026 to add a new cookie, __oppref, associated with OpenAI and classified for advertising and data sale purposes. This cookie now appears …

View change record →
July 24, 2026 medium

Mercury updated its privacy policy to expand how certain cookies are classified and used. Specifically, cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads now include 'SaleOfInfo' …

View change record →
July 16, 2026 low

Mercury updated its privacy policy contact email addresses, changing from a legacy email address to help@mercury.com across four key sections: cookie opt-out inquiries, privacy rights requests, parental inquiries about minors' …

View change record →
June 19, 2026 low

Mercury updated its privacy policy on June 19, 2026 to disclose SMS and MMS messaging practices. The new language states that Mercury may send SMS messages to users who have …

View change record →
June 12, 2026 low

Mercury's privacy policy cookie table was updated on June 12, 2026 to add one new cookie entry and reorder existing entries. A Google Analytics cookie pattern (^_dc_gtm_UA-.*) was added to …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

58 provisions
12 featured
14 clause types
22 high severity
Acceptable Use Restrictions 1 1 high
Disclosure and Transparency Requirements 1 1 high
Restricted or Prohibited Content/Industries 1 1 high
Targeting and Audience Restrictions 1
Stay ahead of the changes

Monitoring

Mercury has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Advertising cookies may constitute sale or sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured September 11, 2026 01:01 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000530
Version ID CA-V-006797
SHA-256 63a7dbb7d261c1b285d83fc7955ab209f7e05021c8e19cce49a325de79168cb2
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans