Mercury · Mercury Privacy Policy · View original document ↗

Data Retention Framework

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mercury changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mercury recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Mercury Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Personal Information is retained based on operational, legal, tax, fraud prevention, dispute resolution, and legal defense factors, without specifying fixed retention periods for any data category, and notes that financial regulatory requirements may require extended retention.

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy does not specify fixed retention timelines for any category of Personal Information, including biometric data, financial records, or audio and video recordings; this approach requires users and compliance teams to rely on Mercury's internal retention schedules rather than disclosed timeframes.

Interpretive note: The criteria-based retention approach without specific period disclosures may meet some jurisdictional requirements (CCPA) while falling short of others (GDPR specificity expectations, BIPA destruction timelines); actual compliance depends on Mercury's internal retention schedule implementation and applicable regulatory interpretation.

Consumer impact (what this means for users)

Under this provision, Mercury retains Personal Information for indeterminate periods based on multiple operational and legal factors; users cannot determine from this policy alone how long specific data categories such as biometric identifiers, financial records, or call recordings will be held.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a deletion request to [email protected] specifying the data categories you wish deleted. Note that deletion may be denied for data subject to legal retention obligations or federal financial regulation exemptions.

Cross-platform context

See how other platforms handle Data Retention Framework and similar clauses.

Compare across platforms →

Monitoring

Mercury has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We retain Personal Information only as long as necessary, and use the following factors to determine the retention period: Provide and maintain our Services Comply with legal and regulatory obligations Meet tax, accounting, and financial reporting requirements Prevent fraud and maintain security Resolve disputes and enforce our agreements Establish, exercise or defend our legal rights Because Mercury operates in a regulated financial environment, certain information may be retained for extended periods as required by law or industry standards.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: GDPR Article 5(1)(e) requires that personal data be retained no longer than necessary for its processing purpose, and European data protection authorities have enforced specific retention schedule disclosure obligations. CCPA and similar U.S. state laws require disclosure of retention periods or criteria for determining them. GLBA and related financial regulations impose minimum retention periods for financial records, which may conflict with deletion rights under state privacy laws. Illinois BIPA requires specific retention schedules and destruction timelines for biometric data. 2) GOVERNANCE EXPOSURE: Medium. The absence of specific retention periods for any data category, particularly biometric data subject to BIPA and audio recordings, creates potential compliance exposure in jurisdictions that require disclosed retention schedules. The general criteria-based approach may satisfy CCPA's disclosure standard but may not meet GDPR's specificity expectations or BIPA's destruction timeline requirements. 3) JURISDICTION FLAGS: Illinois BIPA requires that biometric data be destroyed within three years of collection or when the initial purpose is fulfilled, whichever comes first; this policy does not disclose a biometric-specific retention period. EEA and UK users under GDPR have the right to request erasure where data is retained beyond the necessary period. California residents may request the specific retention period or criteria for their data categories. 4) CONTRACT AND VENDOR IMPLICATIONS: Service providers and business partners receiving Personal Information should have data processing agreements that align with Mercury's retention criteria and specify deletion or return obligations upon contract termination. Biometric data shared with identity verification service providers should be governed by BIPA-compliant destruction timelines in vendor agreements. 5) COMPLIANCE CONSIDERATIONS: Legal teams should develop and document category-specific retention schedules for internal compliance purposes, particularly for biometric data, audio and video recordings, financial records, and marketing data. These schedules should be made available to users upon request consistent with CCPA disclosure obligations. The retention framework should be audited against GLBA, BIPA, and GDPR requirements to identify any gaps between the policy's general criteria and applicable legal minimums or maximums.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • CFPB
    The CFPB has authority over data retention practices for financial records held by non-bank financial institutions under GLBA and related financial regulations
    File a complaint →
  • FTC
    The FTC has authority over data retention representations and practices under its consumer protection and privacy enforcement mandate
    File a complaint →

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015759
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f8b49beb208e6c3f2b9fb8ddafa22b88d22bbef9e6d3e086c87840d1d5a282f8
Analysis generated
July 9, 2026 08:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-015759
Captured: 2026-07-09 08:43:59 UTC
SHA-256: f8b49beb208e6c3f…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-015759/data-retention-framework/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Mercury's Data Retention Framework clause do?

The policy does not specify fixed retention timelines for any category of Personal Information, including biometric data, financial records, or audio and video recordings; this approach requires users and compliance teams to rely on Mercury's internal retention schedules rather than disclosed timeframes.

How does this clause affect you?

Under this provision, Mercury retains Personal Information for indeterminate periods based on multiple operational and legal factors; users cannot determine from this policy alone how long specific data categories such as biometric identifiers, financial records, or call recordings will be held.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.