Provision record
Mercury · Mercury Privacy Policy · View original document ↗

Federal Financial Regulation Exemption from State Privacy Requests

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Mercury and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that privacy rights requests including deletion and access may be denied in part when the Personal Information is subject to federal financial laws that are exempt from U.S. state privacy law requirements, and directs personal account users to a separate Consumer Financial Privacy Notice.

ⓘ

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.

⚠

Interpretive note: The precise boundary of GLBA exemption applicability to specific data categories held by Mercury depends on regulatory interpretation and may vary based on the nature of the financial product and applicable state law, creating potential for inconsistent application across user account types.

Recent Activity

This document changed recently

Medium Aug 28, 2026

The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.

View change record →
Medium Jul 24, 2026

The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.

View change record →

Consumer impact (what this means for users)

Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a privacy request to [email protected] specifying the data you wish to access or delete. If your request is denied, you may appeal by emailing the same address with 'Privacy Request Appeal' in the subject line.

Cross-platform context

See how other platforms handle Federal Financial Regulation Exemption from State Privacy Requests and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Please note that certain requests may be denied where permitted by law. For example, for personal accounts, some Personal Information we may process may be subject to federal laws that are exempt from U.S. state privacy laws. As a result, some requests may be denied in part based on the applicability of these exemptions. For more information on personal accounts, please refer to the Mercury Consumer Financial Privacy Notice to learn more about how we treat your Personal Information.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages the Gramm-Leach-Bliley Act (GLBA), which governs the privacy of nonpublic personal information held by financial institutions, and CCPA's GLBA exemption, which excludes GLBA-covered data from CCPA deletion and access …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Consumer Financial Protection Bureau (cfpb)
    Regulates consumer financial products and services. Can investigate companies for unfair, deceptive, or abusive financial practices including improper fees, billing errors, and data misuse.
    Who can file: Anyone who has used a consumer financial product or service in the US
    What you need: Account number or details, dates of transactions or events, description of the issue, and any supporting documents
    What to expect: The company must respond within 15 days. The CFPB forwards your complaint and may use it in enforcement actions. Individual compensation is possible in some cases.
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015754
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f8b49beb208e6c3f2b9fb8ddafa22b88d22bbef9e6d3e086c87840d1d5a282f8
Analysis generated
July 9, 2026 08:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-015754
Captured: 2026-07-09 08:43:59 UTC
SHA-256: f8b49beb208e6c3f…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-015754/federal-financial-regulation-exemption-from-state-privacy-requests/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Mercury's Federal Financial Regulation Exemption from State Privacy Requests clause do?

This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.

How does this clause affect you?

Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.