Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
The Plaid End User Privacy Policy describes how Plaid collects, retains, and uses financial data including bank account information, transaction history, and login credentials when users connect their bank accounts to third-party applications through Plaid's infrastructure. The policy establishes that Plaid retains financial transaction data for use in network analytics and product improvement purposes independently of the original third-party application connection. Users may access and request deletion of their financial data through Plaid's data portal at my.plaid.com.
This document governs Plaid's collection, use, storage, and sharing of personal and financial data through its data network and API infrastructure, operating under a stated basis of user consent obtained through partner application flows and Plaid's own Link product. The policy states that Plaid collects financial account data (including account numbers, balances, transaction history, and credentials in some flows), identity information, and device/usage data, and the terms authorize sharing this data with financial institution partners, developers building on Plaid's platform, and third-party service providers. Notably, Plaid's data collection model is operationally distinct from many consumer-facing privacy policies in that the end user typically interacts with Plaid through a third-party application rather than directly, creating a layered consent structure where users may not be fully aware of Plaid's role as a data intermediary; the policy asserts broad rights to retain and use transaction data for product improvement and network-level analytics, which the agreement states is done in de-identified or aggregated form, though the scope of re-identification risk under applicable standards warrants evaluation. The policy engages CCPA and CPRA for California residents, GLBA for financial data contexts, and GDPR and UK GDPR for European and UK users respectively, with the FTC and CFPB representing the primary federal enforcement authorities given Plaid's role in financial data intermediation. Compliance teams should note that Plaid entered a 2021 FTC consent order resolving allegations about data collection and use practices, which creates a regulatory baseline against which current policy language should be evaluated, particularly regarding the scope of credential collection and data use for purposes beyond the user's stated transaction.
Institutional analysis available with Professional
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Start Professional free trial4 important changes detected
4 versions captured · Last updated: April 2026
Plaid restructured its account terms to emphasize a new direct-to-consumer Plaid Web-App monitoring service alongside its core financial account connection functionality. The updated language clarifies that a Plaid Account now …
View change record →Plaid's privacy policy was substantially revised on April 3, 2026, with 46 sentences added, 76 removed, and 149 modified. The updated terms shift focus from describing a 'Plaid Account' primarily …
View change record →Monitoring
Plaid has updated this document before.
Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
Professional Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Professional free trialCross-platform context
See how other platforms handle Data Retention and Secondary Use for Network Analytics and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.