Provision record
Peloton · Peloton Privacy Policy · View original document ↗

Contact List Syncing and Automatic Storage

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Peloton changes these terms. Follow Peloton →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Peloton Monitor emails you the same day this changes. The archive stays free.
Follow Peloton →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

When a member enables contact syncing, Peloton accesses, imports, and stores the names, email addresses, and phone numbers of all contacts on the member's mobile device, and continues to automatically re-sync this data periodically until the member actively disables the setting in app Preferences.

This analysis describes what Peloton's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes an ongoing automatic data collection mechanism that operates continuously after initial activation, collecting personal information (name, email, phone number) of third parties who are not Peloton members and have not directly consented to the collection of their information by Peloton. The opt-out mechanism requires affirmative action within the app Preferences to halt both syncing and deletion of stored contact data.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, enabling contact syncing initiates an ongoing automatic import of all device contacts' names, emails, and phone numbers into Peloton's systems, affecting individuals who are not Peloton users and have not consented to this collection. The agreement states that disabling 'Contacts syncing' in the Privacy section of Preferences on your mobile device will stop syncing and delete your contacts information from Peloton's system.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Open the Peloton app, navigate to your Profile, go to the Privacy section of Preferences, and toggle off 'Contacts syncing'. The policy states this will stop syncing and delete your contacts information from Peloton's system.

Cross-platform context

See how other platforms handle Contact List Syncing and Automatic Storage and similar clauses.

Compare across platforms →

Monitoring

Peloton has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Peloton → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you choose to sync your Contacts from your mobile device Peloton will access, import and store the name, email and phone number of your Contacts in order to show Contacts which are currently on Peloton, suggest others we think you may know to build the Peloton community, and make it easy for you to invite your Contacts to join Peloton. [...] If you choose to sync your Contacts via your mobile device, as described above, we will continue to automatically sync them on a periodic basis until you turn off "Contacts syncing" in the Privacy section of Preferences on your mobile device, which will stop synching and delete your Contacts information from our system.

Excerpt from Peloton's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision implicates GDPR Article 6 lawful basis requirements and Article 9 where contact data relates to special category individuals, as well as UK GDPR equivalents. Under GDPR, collecting and storing personal data of non-member third parties without a clear lawful basis applicable to those individuals creates compliance exposure. CCPA and U.S. state privacy laws may classify stored contact data as personal information of third parties, raising questions about notice and consent obligations. The FTC Act's prohibition on unfair or deceptive practices is also relevant given that the individuals whose data is collected are not party to Peloton's terms. GOVERNANCE EXPOSURE: High. The automatic periodic re-syncing of contact data belonging to non-member third parties, without those individuals' direct consent, creates exposure under GDPR's accountability and lawfulness requirements and under various U.S. state privacy frameworks. The provision does not identify a specific lawful basis applicable to the processing of non-member contact data. JURISDICTION FLAGS: Heightened exposure in EU/EEA and UK, where GDPR and UK GDPR require a lawful basis for processing personal data of data subjects regardless of whether those individuals are party to the service agreement. California CCPA exposure depends on whether stored third-party contact data constitutes personal information subject to notice obligations. Illinois and other states with biometric or contact data statutes may create additional considerations. CONTRACT AND VENDOR IMPLICATIONS: Organizations whose employee or customer contact information may be synced by Peloton users should assess whether this practice creates data flow risks relevant to their own GDPR or CCPA obligations. This provision does not establish audit rights or direct contractual obligations on organizations whose data may be captured. COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether the initial opt-in mechanism for contact syncing constitutes informed consent under applicable law, whether the periodic automatic re-sync requires a separate or refreshed consent trigger, and whether the deletion mechanism upon opt-out is verifiable and auditable. Data mapping exercises should account for third-party contact data as a distinct data category with separate processing purposes and lawful basis requirements.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer privacy practices and unfair or deceptive data collection practices, including collection of third-party individuals' contact data without direct notice.
    File a complaint →

Provision details

Document information
Document
Peloton Privacy Policy
Entity
Peloton
Document last updated
May 5, 2026
Tracking information
First tracked
April 27, 2026
Last verified
July 9, 2026
Record ID
CA-P-015946
Document ID
CA-D-00220
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dc94d4de5c0a32807ebe04a1fad05e9914d9dffe0165262b81083c5a41020389
Analysis generated
April 27, 2026 14:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Peloton
Document: Peloton Privacy Policy
Record ID: CA-P-015946
Captured: 2026-04-27 14:37:01 UTC
SHA-256: dc94d4de5c0a3280…
URL: https://conductatlas.com/platform/peloton/peloton-privacy-policy/provision/CA-P-015946/contact-list-syncing-and-automatic-storage/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Peloton's Contact List Syncing and Automatic Storage clause do?

This provision establishes an ongoing automatic data collection mechanism that operates continuously after initial activation, collecting personal information (name, email, phone number) of third parties who are not Peloton members and have not directly consented to the collection of their information by Peloton. The opt-out mechanism requires affirmative action within the app Preferences to halt both syncing and deletion of …

How does this clause affect you?

Under this clause, enabling contact syncing initiates an ongoing automatic import of all device contacts' names, emails, and phone numbers into Peloton's systems, affecting individuals who are not Peloton users and have not consented to this collection. The agreement states that disabling 'Contacts syncing' in the Privacy section of Preferences on your mobile device will stop syncing and delete your …

Is ConductAtlas affiliated with Peloton?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Peloton.