The policy states that privacy rights requests including deletion and access may be denied in part when the Personal Information is subject to federal financial laws that are exempt from U.S. state privacy law requirements, and directs personal account users to a separate Consumer Financial Privacy Notice.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.
Interpretive note: The precise boundary of GLBA exemption applicability to specific data categories held by Mercury depends on regulatory interpretation and may vary based on the nature of the financial product and applicable state law, creating potential for inconsistent application across user account types.
The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.
View change record →The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.
View change record →Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.
Cross-platform context
See how other platforms handle Federal Financial Regulation Exemption from State Privacy Requests and similar clauses.
Compare across platforms →"Please note that certain requests may be denied where permitted by law. For example, for personal accounts, some Personal Information we may process may be subject to federal laws that are exempt from U.S. state privacy laws. As a result, some requests may be denied in part based on the applicability of these exemptions. For more information on personal accounts, please refer to the Mercury Consumer Financial Privacy Notice to learn more about how we treat your Personal Information.Excerpt from Mercury's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages the Gramm-Leach-Bliley Act (GLBA), which governs the privacy of nonpublic personal information held by financial institutions, and CCPA's GLBA exemption, which excludes GLBA-covered data from CCPA deletion and access …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.
Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.