Mixpanel · Mixpanel Terms of Use · View original document ↗

Prohibition on Sensitive Personal Data Without Authorization

High severity Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Mixpanel Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Businesses using Mixpanel are not allowed to send Mixpanel data about users' health, finances, government IDs, biometrics, or children's information unless Mixpanel specifically approves it in writing.

This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Many analytics implementations inadvertently capture sensitive data — for example, through form field tracking or URL parameters — and this clause makes the customer solely responsible for preventing such transmissions, creating regulatory exposure under HIPAA, COPPA, and financial privacy laws if violations occur.

Recent Activity

This document changed recently

Medium May 9, 2026

The updated terms establish an automatic 7% fee increase mechanism that takes effect upon each subscription renewal. Previously, subscription fees remained fixed for the duration of the subscription …

Consumer impact (what this means for users)

If a business accidentally sends your health, financial, or children's data to Mixpanel through its analytics tracking, that business — not Mixpanel — bears full legal responsibility for the violation, and Mixpanel's terms explicitly prohibit such transmissions without prior written approval.

How other platforms handle this

X Medium

You may not access the Services in any way other than through the currently available, published interfaces that we provide. For example, this means that you cannot scrape the Services without X's express written permission, try to work around any technical limitations we impose, or otherwise attemp...

Google Maps Medium

You must not pre-fetch, cache, index, or store any Content, except that you may store: (i) limited amounts of Content for the purpose of improving the performance of your Maps API Implementation, but only for a temporary period as specified in the Maps APIs Documentation; and (ii) any content that G...

Meta Medium

You must not sell, license, or purchase User Data obtained from us. You must not transfer User Data obtained from us without our prior written permission except when: transferring to your service provider acting on your behalf and in compliance with this Policy; transferring as part of a merger, acq...

See all platforms with this clause type →

Monitoring

Mixpanel has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer will not submit to the Service any Sensitive Personal Information without Mixpanel's express written authorization. Sensitive Personal Information includes health or medical information, financial account information, social security numbers or government-issued identification numbers, biometric data, information relating to children under the age of 13 (or the applicable age of digital consent in the relevant jurisdiction), and other categories of sensitive personal information as defined under applicable law.

— Excerpt from Mixpanel's Mixpanel Terms of Use

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY FRAMEWORK: This provision directly implicates COPPA 16 CFR Part 312 (prohibition on collecting personal information from children under 13 without verifiable parental consent), enforced by the FTC; HIPAA 45 CFR §§164.502 and 164.514 (restrictions on PHI disclosure), enforced by HHS OCR; GLBA 15 U.S.C. §6802 (financial data privacy), enforced by federal financial regulators; GDPR Art. 9 (special categories of personal data requiring explicit consent); and CCPA §1798.121 (sensitive personal information rights). The EU AI Act's provisions on biometric data processing may also apply where biometric identifiers are involved. (2)

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    FTC enforces COPPA restrictions on children's data collection and has taken action against analytics platforms and their customers for unauthorized collection of children's behavioral data.
    File a complaint →
  • Hhs Ocr
    HHS OCR enforces HIPAA restrictions on health data disclosure to third parties, including analytics providers, and has issued specific guidance on tracking technologies capturing PHI.
    File a complaint →

Applicable regulations

CFAA
United States Federal
DSA
European Union

Provision details

Document information
Document
Mixpanel Terms of Use
Entity
Mixpanel
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 7, 2026
Record ID
CA-P-005724
Document ID
CA-D-00703
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
67c0caf5d98d0ef754fe77df373e5ce756690436f170028f83d38e42249bf604
Analysis generated
May 7, 2026 23:56 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mixpanel
Document: Mixpanel Terms of Use
Record ID: CA-P-005724
Captured: 2026-05-07 23:56:18 UTC
SHA-256: 67c0caf5d98d0ef7…
URL: https://conductatlas.com/platform/mixpanel/mixpanel-terms-of-use/prohibition-on-sensitive-personal-data-without-authorization/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Mixpanel's Prohibition on Sensitive Personal Data Without Authorization clause do?

Many analytics implementations inadvertently capture sensitive data — for example, through form field tracking or URL parameters — and this clause makes the customer solely responsible for preventing such transmissions, creating regulatory exposure under HIPAA, COPPA, and financial privacy laws if violations occur.

How does this clause affect you?

If a business accidentally sends your health, financial, or children's data to Mixpanel through its analytics tracking, that business — not Mixpanel — bears full legal responsibility for the violation, and Mixpanel's terms explicitly prohibit such transmissions without prior written approval.

Is ConductAtlas affiliated with Mixpanel?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.