Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Users grant Mercury a license to collect, use, disclose, combine, transmit, format, and display user content, and separately grant Mercury rights to aggregate data generated from platform use for Mercury's own business purposes. The scope of permitted business purposes is not defined within the Terms of Use itself and is referenced to the privacy policy.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes two distinct data rights: a content license covering user-submitted information and a separate aggregated data right covering platform-generated usage data. The aggregated Site Data right is not limited to specific business purposes within the agreement text, with further definition deferred to Mercury's privacy policy, creating a dependency on that document for full scope assessment.
Interpretive note: The permitted scope of 'business purposes' for aggregated Site Data is defined by reference to Mercury's privacy policy rather than within the Terms of Use, and full assessment of this provision requires review of that companion document.
Mercury's updated terms establish detailed rules for how recurring autopay works on invoices. Under the revised language, payers authorize recurring ACH debits through a separate addendum, Mercury will not retry failed payments (except once if caused by a Mercury system issue), and autopay authorization will automatically cancel after two consecutive failures in a series. You can prevent autopay cancellation by ensuring payers have sufficient funds, re-enrolling the payer, or requesting manual payment if the series fails twice.
View change record →The updated terms establish that when customers pay invoices you issue through Mercury Invoicing via ACH debit, Mercury will apply a hold period before crediting the funds to your account. The hold period is determined by Mercury in its sole discretion based on risk factors related to the transaction, payer, and payment history, and may range from 1 to 4 business days from the date the ACH debit is initiated. Mercury will display an estimated funds availability date for each incoming invoice payment in your Invoicing dashboard.
View change record →The agreement grants Mercury rights to aggregate platform usage data and use it for Mercury's business purposes. The specific permitted business purposes for aggregated site data are defined by reference to Mercury's privacy policy rather than within the Terms of Use itself.
Cross-platform context
See how other platforms handle Data Aggregation License and similar clauses.
Compare across platforms →Monitoring
Mercury has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"By using the Services, you grant Mercury a non-exclusive, royalty-free, license during the term to collect, use, disclose, combine, transmit, format, and display User Content for the purposes provided in the privacy policy. Additionally, you grant Mercury the right to aggregate data we collect from your use of the Services ("Site Data") and use such Site Data for our business purposes.Excerpt from Mercury's Terms of Service
1) REGULATORY LANDSCAPE: This provision engages GDPR principles of purpose limitation and data minimization for EU-connected users, CCPA disclosure and opt-out requirements for California residents regarding commercial use of personal information, and FTC Act requirements related to unfair or deceptive data practices. The agreement references GDPR and CCPA compliance in Section 5 in the context of promotional data collection but does not specify GDPR legal bases for the data aggregation license in Section 3. 2) GOVERNANCE EXPOSURE: Medium. The aggregated Site Data right is granted for Mercury's business purposes without defined limits within the Terms of Use. Organizations subject to GDPR should evaluate whether Mercury's privacy policy establishes a lawful basis for this aggregation under Articles 6 and 89 of the GDPR, and whether data processing agreements (DPAs) are in place with Mercury as a data processor or controller. 3) JURISDICTION FLAGS: EU and EEA users face heightened exposure under GDPR purpose limitation and data minimization requirements. California residents should evaluate whether the aggregated data use constitutes a sale or sharing of personal information under CCPA, which would trigger opt-out rights. The document states that user content is submitted at the user's own risk regarding security, which may interact with GDPR controller accountability obligations. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether a data processing agreement exists separately from the Terms of Use, as the Terms of Use alone do not specify whether Mercury acts as a data processor or controller with respect to aggregated site data. Organizations onboarding Mercury should map what categories of data are captured as Site Data and whether any such data includes personal information subject to heightened protection. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should review Mercury's privacy policy as a companion document to assess the full scope of permitted business purposes for Site Data aggregation. GDPR-subject organizations should confirm whether Mercury provides standard contractual clauses or equivalent transfer mechanisms for data processed outside the EU. CCPA-subject organizations should confirm whether Mercury's data aggregation practices are disclosed in their vendor data inventory.
This provision establishes two distinct data rights: a content license covering user-submitted information and a separate aggregated data right covering platform-generated usage data. The aggregated Site Data right is not limited to specific business purposes within the agreement text, with further definition deferred to Mercury's privacy policy, creating a dependency on that document for full scope assessment.
The agreement grants Mercury rights to aggregate platform usage data and use it for Mercury's business purposes. The specific permitted business purposes for aggregated site data are defined by reference to Mercury's privacy policy rather than within the Terms of Use itself.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.