The policy states that Mercury uses AI and machine learning for fraud detection, credit application evaluation, document verification, and transaction categorization, and that decisions with legal consequences, financial implications, or material effects on service access always include human oversight rather than being made by AI alone.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Mercury's stated operational safeguard against fully automated consequential decision-making, which is relevant to GDPR Article 22 requirements for EEA users and to emerging U.S. state automated decision-making regulations; the policy does not specify the mechanism or documentation standard for human oversight.
Interpretive note: The policy does not specify the operational mechanism or documentation standard for 'appropriate human oversight,' and the extent to which this commitment satisfies GDPR Article 22 or U.S. state automated decision-making requirements depends on jurisdiction-specific enforcement interpretation.
The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.
View change record →The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.
View change record →Under this provision, credit application evaluations and other decisions materially affecting service access involve human oversight as stated by Mercury; however, the policy does not describe a formal right to explanation or contest automated decisions beyond the general privacy rights outlined in Section 9.
Cross-platform context
See how other platforms handle AI-Assisted Decision-Making with Human Oversight and similar clauses.
Compare across platforms →"We use artificial intelligence ('AI') and machine learning technologies to enhance security, streamline operations, and deliver personalized, efficient services for our customers. We may apply these tools to analyze information we collect for purposes such as verifying documents, categorizing businesses, detecting fraud, supporting customer service, evaluating credit applications, categorizing transactions, and other legitimate functions. While AI helps us work faster and smarter, we do not rely on it alone to make decisions that could have legal consequences, financial implications, or otherwise materially affect your rights or access to our services. Such decisions always involve appropriate human oversight.Excerpt from Mercury's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Article 22, which restricts fully automated individual decision-making that produces legal or similarly significant effects, and requires that such decisions involve human review upon request.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes Mercury's stated operational safeguard against fully automated consequential decision-making, which is relevant to GDPR Article 22 requirements for EEA users and to emerging U.S. state automated decision-making regulations; the policy does not specify the mechanism or documentation standard for human oversight.
Under this provision, credit application evaluations and other decisions materially affecting service access involve human oversight as stated by Mercury; however, the policy does not describe a formal right to explanation or contest automated decisions beyond the general privacy rights outlined in Section 9.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.