When you use a third-party app that runs Mixpanel's analytics tools, Mixpanel handles your data on behalf of that app's owner, not on its own behalf, which means your data rights must generally be directed to that app rather than to Mixpanel.
This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision determines who is responsible for your personal data and where you must direct rights requests; end users of apps built on Mixpanel's platform may have limited direct recourse against Mixpanel itself.
If your data is collected through a third-party product that uses Mixpanel's analytics, the policy states Mixpanel's obligations to you are governed by its contract with that product's operator, not by this privacy policy directly; you must contact that operator to exercise deletion, correction, or access rights.
How other platforms handle this
At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.
If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...
We may display advertisements on our Services and those advertisements may be targeted to your interests based on your personal information. We may share your personal information with advertising partners for interest-based advertising purposes. You may opt out of interest-based advertising by visi...
Monitoring
Mixpanel has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Mixpanel acts as a 'data controller' when we collect and use personal data for our own purposes, such as information about visitors to our website or customers who use our Service. Mixpanel acts as a 'data processor' when we process personal data on behalf of our customers. In this case, our customers are the data controllers and determine the purposes and means of processing. If you are an end user of one of our customers' products and have questions about how your data is handled, please contact that customer directly.— Excerpt from Mixpanel's Mixpanel Privacy Statement
1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 4(7) and 4(8) defining controller and processor roles, and the associated obligations under GDPR Articles 24 through 28 requiring documented data processing agreements. The Irish Data Protection Commission is identified as the lead supervisory authority for EU matters. Under CCPA, the equivalent distinction between business and service provider is similarly operative, with the California Privacy Protection Agency as relevant enforcement authority. 2) GOVERNANCE EXPOSURE: High. The controller/processor distinction has direct compliance consequences for organizations deploying Mixpanel. If a Mixpanel customer transmits personal data to Mixpanel without an executed Data Processing Addendum, that organization may be operating outside GDPR Article 28 requirements, creating regulatory exposure. The policy places the burden on the business customer to handle end-user data rights requests, which requires that those customers have implemented appropriate intake and response processes. 3) JURISDICTION FLAGS: EU and UK deployments face the highest exposure given mandatory DPA requirements under GDPR and UK GDPR. California-resident data processed through Mixpanel by a third-party business triggers CCPA service provider agreement requirements. Deployments involving minors' data may engage COPPA, where the operator/processor chain requires heightened diligence. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams must confirm execution of Mixpanel's Data Processing Addendum prior to deployment. The policy's assertion that Mixpanel acts only on customer instructions as a processor should be verified against the actual DPA terms, including sub-processor lists, audit rights, and breach notification obligations. Organizations should assess whether Mixpanel's standard DPA terms align with their own regulatory obligations. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should confirm DPA execution, review sub-processor disclosure lists, and update their own privacy notices to accurately reflect Mixpanel's involvement in data processing. Data subject rights intake procedures should be mapped to include forwarding obligations where requests concern data processed through Mixpanel's platform.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision determines who is responsible for your personal data and where you must direct rights requests; end users of apps built on Mixpanel's platform may have limited direct recourse against Mixpanel itself.
If your data is collected through a third-party product that uses Mixpanel's analytics, the policy states Mixpanel's obligations to you are governed by its contract with that product's operator, not by this privacy policy directly; you must contact that operator to exercise deletion, correction, or access rights.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.