The policy states that Personal Information is retained based on operational, legal, tax, fraud prevention, dispute resolution, and legal defense factors, without specifying fixed retention periods for any data category, and notes that financial regulatory requirements may require extended retention.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy does not specify fixed retention timelines for any category of Personal Information, including biometric data, financial records, or audio and video recordings; this approach requires users and compliance teams to rely on Mercury's internal retention schedules rather than disclosed timeframes.
Interpretive note: The criteria-based retention approach without specific period disclosures may meet some jurisdictional requirements (CCPA) while falling short of others (GDPR specificity expectations, BIPA destruction timelines); actual compliance depends on Mercury's internal retention schedule implementation and applicable regulatory interpretation.
The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.
View change record →The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.
View change record →Under this provision, Mercury retains Personal Information for indeterminate periods based on multiple operational and legal factors; users cannot determine from this policy alone how long specific data categories such as biometric identifiers, financial records, or call recordings will be held.
Cross-platform context
See how other platforms handle Data Retention Framework and similar clauses.
Compare across platforms →"We retain Personal Information only as long as necessary, and use the following factors to determine the retention period: Provide and maintain our Services Comply with legal and regulatory obligations Meet tax, accounting, and financial reporting requirements Prevent fraud and maintain security Resolve disputes and enforce our agreements Establish, exercise or defend our legal rights Because Mercury operates in a regulated financial environment, certain information may be retained for extended periods as required by law or industry standards.Excerpt from Mercury's Privacy Policy
1) REGULATORY LANDSCAPE: GDPR Article 5(1)(e) requires that personal data be retained no longer than necessary for its processing purpose, and European data protection authorities have enforced specific retention schedule disclosure obligations.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy does not specify fixed retention timelines for any category of Personal Information, including biometric data, financial records, or audio and video recordings; this approach requires users and compliance teams to rely on Mercury's internal retention schedules rather than disclosed timeframes.
Under this provision, Mercury retains Personal Information for indeterminate periods based on multiple operational and legal factors; users cannot determine from this policy alone how long specific data categories such as biometric identifiers, financial records, or call recordings will be held.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.