Provision record
Mercury · Mercury Privacy Policy · View original document ↗

Collection of Beneficial Owner and Authorized User Data

Medium severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track Mercury and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

When a business opens a Mercury account, personal information about the business's owners and other authorized individuals is also collected and processed, even if those individuals are not the primary account applicant.

ⓘ

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Individual employees, owners, and signatories associated with a Mercury business account have their personal data collected and governed by this policy, which may not be obvious to those individuals who did not themselves sign up for Mercury.

⚠

Interpretive note: The precise scope of individual data subject rights for beneficial owners and authorized users under Mercury's policy is not fully detailed in the available document text.

Recent Activity

This document changed recently

Medium Aug 28, 2026

The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.

View change record →
Medium Jul 24, 2026

The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.

View change record →

Consumer impact (what this means for users)

Business owners and authorized users who are associated with a Mercury account have their personal identity and financial data collected under this policy, potentially without independent notice or consent as individuals.

How other platforms handle this

ClickUp Medium

If you are an end user in a Workspace not owned by you and wish to update, delete, or receive any information we have about you, you may do so by contacting the organization who owns your ClickUp Workspace.

Notion Medium

You have the right to submit a request through an authorized agent, but we will require the agent to provide us with your written permission, and we may need to confirm your identity before processing the agent's request.

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
When you open a business account with us, we collect information about the beneficial owners and authorized signatories of your business, including personal identifiers, identity verification information, and financial information. Individuals associated with your account may also be subject to this Privacy Policy.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: Collection of personal data from beneficial owners and authorized users at account opening is required under FinCEN's Customer Due Diligence Rule for financial institutions, which mandates collection of beneficial ownership information.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Consumer Financial Protection Bureau (cfpb)
    Regulates consumer financial products and services. Can investigate companies for unfair, deceptive, or abusive financial practices including improper fees, billing errors, and data misuse.
    Who can file: Anyone who has used a consumer financial product or service in the US
    What you need: Account number or details, dates of transactions or events, description of the issue, and any supporting documents
    What to expect: The company must respond within 15 days. The CFPB forwards your complaint and may use it in enforcement actions. Individual compensation is possible in some cases.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-009921
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3d6aa369f801696c18c9d0fc76a52e05f31b7831be748c05895341caee7b216d
Analysis generated
May 8, 2026 11:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-009921
Captured: 2026-05-08 11:54:36 UTC
SHA-256: 3d6aa369f801696c…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-009921/collection-of-beneficial-owner-and-authorized-user-data/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Mercury's Collection of Beneficial Owner and Authorized User Data clause do?

Individual employees, owners, and signatories associated with a Mercury business account have their personal data collected and governed by this policy, which may not be obvious to those individuals who did not themselves sign up for Mercury.

How does this clause affect you?

Business owners and authorized users who are associated with a Mercury account have their personal identity and financial data collected under this policy, potentially without independent notice or consent as individuals.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.