The policy states that Personal Information may be stored and processed in any country where Mercury or its affiliates and service providers operate, and that EEA and UK transfers are protected by Standard Contractual Clauses and additional technical safeguards.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.
Interpretive note: The policy references SCCs and 'additional technical and organizational safeguards' without specifying the nature of supplementary measures or confirming transfer impact assessments, which are required under post-Schrems II regulatory guidance; actual compliance depends on operational implementation not described in the document.
The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.
View change record →The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.
View change record →Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.
Cross-platform context
See how other platforms handle International Data Transfers and Standard Contractual Clauses and similar clauses.
Compare across platforms →"Mercury is headquartered in the United States, and we may store and process Personal Information in the United States or any other country in which we or our affiliates, business partners, or service providers operate. Our Services are primarily intended for individuals and businesses operating in the United States. If you are located outside the United States, your Personal Information may be transferred to and processed in jurisdictions that may not provide the same level of data protection as your home country. When we transfer Personal Information across borders, we implement safeguards required under applicable law. For example, for transfers from the European Economic Area or United Kingdom, we rely on approved contractual protections (such as Standard Contractual Clauses) and additional technical and organizational safeguards designed to ensure your information remains protected.Excerpt from Mercury's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (Articles 44-49) governing international data transfers from the EEA, and the UK GDPR's equivalent transfer restriction provisions.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.
Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.