This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Biometric information is among the most sensitive categories of personal data; its collection by Mercury has significant implications for user privacy and data security.
Interpretive note: The excerpt identifies biometric information as a category collected but does not specify the precise purpose or context of collection beyond the clause name referencing identity purposes. The purpose 'identity' is drawn from the clause name, not the quoted language itself.
The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.
View change record →The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.
View change record →Mercury collects your biometric data, which may include your voiceprint, facial scan, and biometrics derived from photographs or images.
How other platforms handle this
do not collect financial payment or banking information unless this is required for the use of specific features.
We collect data about your interactions with the Services, such as IP address, device information, session details, date and time of requests, device type and ID, operating system and application version...
Category A: Identifiers. Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, driver's license number, passport number... Collected: Yes.
"Biometric information, such as voiceprint, facial scan, and biometrics extracted from a photograph or image.Excerpt from Mercury's Privacy Policy
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Biometric information is among the most sensitive categories of personal data; its collection by Mercury has significant implications for user privacy and data security.
Mercury collects your biometric data, which may include your voiceprint, facial scan, and biometrics derived from photographs or images.
ConductAtlas has identified this type of provision across 299 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.