Mercury · Mercury Terms of Service · View original document ↗

Data Aggregation License

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mercury changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mercury recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Mercury Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Users grant Mercury a license to collect, use, disclose, combine, transmit, format, and display user content, and separately grant Mercury rights to aggregate data generated from platform use for Mercury's own business purposes. The scope of permitted business purposes is not defined within the Terms of Use itself and is referenced to the privacy policy.

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes two distinct data rights: a content license covering user-submitted information and a separate aggregated data right covering platform-generated usage data. The aggregated Site Data right is not limited to specific business purposes within the agreement text, with further definition deferred to Mercury's privacy policy, creating a dependency on that document for full scope assessment.

Interpretive note: The permitted scope of 'business purposes' for aggregated Site Data is defined by reference to Mercury's privacy policy rather than within the Terms of Use, and full assessment of this provision requires review of that companion document.

Recent Activity

This document changed recently

Medium Jun 26, 2026

Mercury's updated terms establish detailed rules for how recurring autopay works on invoices. Under the revised language, payers authorize recurring ACH debits through a separate addendum, Mercury will not retry failed payments (except once if caused by a Mercury system issue), and autopay authorization will automatically cancel after two consecutive failures in a series. You can prevent autopay cancellation by ensuring payers have sufficient funds, re-enrolling the payer, or requesting manual payment if the series fails twice.

View change record →
Medium May 29, 2026

The updated terms establish that when customers pay invoices you issue through Mercury Invoicing via ACH debit, Mercury will apply a hold period before crediting the funds to your account. The hold period is determined by Mercury in its sole discretion based on risk factors related to the transaction, payer, and payment history, and may range from 1 to 4 business days from the date the ACH debit is initiated. Mercury will display an estimated funds availability date for each incoming invoice payment in your Invoicing dashboard.

View change record →

Consumer impact (what this means for users)

The agreement grants Mercury rights to aggregate platform usage data and use it for Mercury's business purposes. The specific permitted business purposes for aggregated site data are defined by reference to Mercury's privacy policy rather than within the Terms of Use itself.

Cross-platform context

See how other platforms handle Data Aggregation License and similar clauses.

Compare across platforms →

Monitoring

Mercury has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
By using the Services, you grant Mercury a non-exclusive, royalty-free, license during the term to collect, use, disclose, combine, transmit, format, and display User Content for the purposes provided in the privacy policy. Additionally, you grant Mercury the right to aggregate data we collect from your use of the Services ("Site Data") and use such Site Data for our business purposes.

Excerpt from Mercury's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages GDPR principles of purpose limitation and data minimization for EU-connected users, CCPA disclosure and opt-out requirements for California residents regarding commercial use of personal information, and FTC Act requirements related to unfair or deceptive data practices. The agreement references GDPR and CCPA compliance in Section 5 in the context of promotional data collection but does not specify GDPR legal bases for the data aggregation license in Section 3. 2) GOVERNANCE EXPOSURE: Medium. The aggregated Site Data right is granted for Mercury's business purposes without defined limits within the Terms of Use. Organizations subject to GDPR should evaluate whether Mercury's privacy policy establishes a lawful basis for this aggregation under Articles 6 and 89 of the GDPR, and whether data processing agreements (DPAs) are in place with Mercury as a data processor or controller. 3) JURISDICTION FLAGS: EU and EEA users face heightened exposure under GDPR purpose limitation and data minimization requirements. California residents should evaluate whether the aggregated data use constitutes a sale or sharing of personal information under CCPA, which would trigger opt-out rights. The document states that user content is submitted at the user's own risk regarding security, which may interact with GDPR controller accountability obligations. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether a data processing agreement exists separately from the Terms of Use, as the Terms of Use alone do not specify whether Mercury acts as a data processor or controller with respect to aggregated site data. Organizations onboarding Mercury should map what categories of data are captured as Site Data and whether any such data includes personal information subject to heightened protection. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should review Mercury's privacy policy as a companion document to assess the full scope of permitted business purposes for Site Data aggregation. GDPR-subject organizations should confirm whether Mercury provides standard contractual clauses or equivalent transfer mechanisms for data processed outside the EU. CCPA-subject organizations should confirm whether Mercury's data aggregation practices are disclosed in their vendor data inventory.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC holds jurisdiction over unfair or deceptive data practices and consumer data aggregation disclosures by non-bank financial service providers.
    File a complaint →

Provision details

Document information
Document
Mercury Terms of Service
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014135
Document ID
CA-D-00529
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3ac7ab54812d292da7660282e68a275955e77d625774ffe806d425e9b70bcc72
Analysis generated
July 9, 2026 04:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Terms of Service
Record ID: CA-P-014135
Captured: 2026-07-09 04:51:50 UTC
SHA-256: 3ac7ab54812d292d…
URL: https://conductatlas.com/platform/mercury/mercury-terms-of-service/provision/CA-P-014135/data-aggregation-license/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Mercury's Data Aggregation License clause do?

This provision establishes two distinct data rights: a content license covering user-submitted information and a separate aggregated data right covering platform-generated usage data. The aggregated Site Data right is not limited to specific business purposes within the agreement text, with further definition deferred to Mercury's privacy policy, creating a dependency on that document for full scope assessment.

How does this clause affect you?

The agreement grants Mercury rights to aggregate platform usage data and use it for Mercury's business purposes. The specific permitted business purposes for aggregated site data are defined by reference to Mercury's privacy policy rather than within the Terms of Use itself.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.