9 Total
1 High severity
8 Medium severity
0 Low severity
Summary

This document establishes Poshmark's data collection and use practices for users engaging in buying, selling, and browsing on its fashion resale platform. The policy authorizes collection of personal information including name, address, payment details, device identifiers, photos, and user activity, with provisions permitting disclosure to business partners for marketing and advertising purposes. User-generated content posted publicly on the platform, including profiles, listings, and comments, remains accessible to other users and third parties and may persist following account deletion.

Technical / Legal Breakdown

This document is Poshmark's Privacy Policy, governing the collection, use, disclosure, and retention of personal information from users of the Poshmark platform, a peer-to-peer social commerce marketplace, with a stated legal basis rooted in contractual necessity, consent, and legitimate business interests. The policy states that Poshmark collects a broad range of personal data including name, address, payment information, device identifiers, geolocation, photos, browsing and purchase history, and social graph connections, and the terms authorize use of this data for purposes including personalization, advertising, analytics, fraud prevention, and sharing with third-party business partners and service providers. Notably, the policy reserves the right to share personal information with a wide category of 'business partners' for marketing purposes and authorizes cross-context behavioral advertising, which the terms separately acknowledge may constitute a 'sale' or 'sharing' of personal data under California law, creating opt-out obligations; the breadth of the business partner sharing category and the public nature of user-generated content on the platform are operationally distinct from many consumer platforms where social visibility is more limited. The policy explicitly engages California Consumer Privacy Act and California Privacy Rights Act frameworks, providing opt-out mechanisms for data sale and sharing and sensitive data use, and acknowledges obligations to Nevada, Virginia, Colorado, Connecticut, and Utah residents, as well as referencing GDPR-equivalent obligations for users in certain international regions; enforcement context and the scope of applicable state privacy laws continue to evolve, and the practical enforceability of specific terms may vary by jurisdiction. Compliance teams should note that Poshmark's status as a social commerce platform means user-generated content, including photos and profile information, is broadly public by default, and the policy's treatment of publicly posted data as outside standard deletion or restriction rights warrants careful review.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

2 important changes detected

3 versions captured · Last updated: April 2026

What changed Poshmark significantly expanded and restructured its Privacy Policy on April 19, 2026, adding 249 sentences to provide detailed disclosure of data collection, use, and sharing practices. The updated policy now explicitly describes what types of personal data the company collects (including names, addresses, payment information, photos, videos, and interaction data), how it uses that data, and how consumers can exercise their rights. The prior version was much shorter and less detailed, so this change increases transparency about Poshmark's data practices but does not appear to announce new data uses or remove consumer protections.
Why this matters Poshmark's updated Privacy Policy provides significantly more transparent disclosure about what personal data the company collects, how it uses that data, and how you can exercise your privacy rights. The policy now explicitly itemizes data collection points, including photos, videos, payment information, social media accounts, and user interaction data, and provides a dedicated section on consumer rights and choices. The policy also includes a dedicated California Privacy Notice supplement, indicating enhanced compliance with California privacy laws. You can review the full updated policy and California Privacy Notice to understand Poshmark's specific data practices and identify which privacy rights and choices are available to you.
View full change record →
What changed Poshmark expanded and reorganized its privacy policy on March 25, 2026, adding 249 sentences of new content that detail what data the company collects, how it uses that data, and user rights. The updated policy now explicitly describes collection of information you provide directly (name, address, phone, email, sizing preferences), data generated when using the service (listings, photos, videos, purchase history, interactions with other users), and payment information for transactions. This represents a shift from the previous version toward more granular disclosure of data collection practices, though the actual data handling practices may not have changed.
Why this matters Poshmark's updated privacy policy provides more explicit detail about what categories of personal data the company collects through the platform, including user-generated content (photos, videos, listings), interaction data (likes, comments, offers), and payment information. The expanded disclosure does not necessarily indicate new data collection practices, but gives users clearer visibility into what information Poshmark holds. You can review the full policy at Poshmark's website to understand which data collection practices apply to your account activity and, if you are a California resident, consult the supplementary California Privacy Notice referenced in the policy.
View full change record →

High — 1 provision
Medium — 8 provisions

Monitoring

Poshmark has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Business Partner Data Sharing for Marketing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:30 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000334
Version ID CA-V-000824
SHA-256 e8c42ef424cd6f3506430b58e5fd038e4d01ffc2494d19081e184f34ba50dcca
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans