8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

This document establishes PlanetScale's data collection, use, and disclosure practices for personal data obtained through its database platform and website. The policy authorizes PlanetScale to collect identifiers, device data, online activity, and behavioral inferences, and permits sharing of identifiers, usage data, and behavioral inferences with third-party advertising partners for interest-based advertising purposes. Users may opt out of this sharing through the 'Do Not Share My Personal Information' mechanism in the website footer or via cookie settings adjustment.

Technical / Legal Breakdown

This Privacy Policy, last updated October 26, 2023, governs PlanetScale Inc.'s handling of personal information collected through its website, database platform, and related services, treating all covered data as pertaining to individuals acting in a business representative capacity rather than a personal or household capacity. The policy states that PlanetScale collects contact details, account credentials, payment information (processed by Stripe), usage data, device and online activity data, marketing data, and inferences; the terms authorize sharing this information with service providers, advertising partners, professional advisors, law enforcement, and business transferees in merger or acquisition scenarios. Notably, the policy explicitly carves out data processed on behalf of enterprise customers as a service provider or processor, meaning that data falls outside this policy's scope entirely, which is operationally significant for B2B customers assessing their own compliance obligations. The policy engages GDPR and UK GDPR through its appointment of EU and UK data representatives (Verasafe) and reliance on EU Commission and UK government adequacy decisions or contractual safeguards for cross-border transfers; it also participates in the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US Data Privacy Framework, with PlanetScale expressly subject to FTC investigatory and enforcement authority. California residents should note the detailed CCPA-aligned Privacy Snapshot disclosing data categories, collection sources, processing purposes, and sharing limitations, including a 'Do Not Share My Personal Information' opt-out for interest-based advertising, though the policy clarifies that personal information is not sold.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial
High — 1 provision
Medium — 6 provisions
Low — 1 provision

Monitoring

PlanetScale has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Enterprise Customer Data Processor Carve-Out and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:38 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000684
Version ID CA-V-001321
SHA-256 2b2c9ae3a502b44543bf2d8fee53006e16f531dbc44f48fcce4a77112287a8a5
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans