Public can share data that has been stripped of personal identifiers with outside companies for purposes like research and marketing, and this sharing is not subject to the same restrictions as personal data.
This analysis describes what Public.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy asserts that aggregated or de-identified data falls outside normal privacy protections, but the robustness of de-identification is not independently verified in the policy text, and re-identification risks exist particularly with detailed financial behavioral data.
Interpretive note: The policy asserts that de-identified data cannot reasonably be used to identify individuals, but does not disclose the technical standard applied. Whether this assertion satisfies applicable legal standards depends on the actual methodology, which is not available in the policy text.
Your trading behavior and account activity may inform research and marketing products shared with third parties after being aggregated or de-identified. The policy does not specify the de-identification standard applied, so users cannot independently assess the re-identification risk.
How other platforms handle this
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...
Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).
"We may also share aggregated or de-identified information, which cannot reasonably be used to identify you, with third parties for research, marketing, analytics, and other purposes.Excerpt from Public.com's Privacy Policy
REGULATORY LANDSCAPE: CCPA/CPRA and other state privacy laws typically exempt truly de-identified data from consumer rights requirements, but CPRA imposes an obligation on businesses to implement processes to prevent re-identification and to contractually prohibit recipients …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy asserts that aggregated or de-identified data falls outside normal privacy protections, but the robustness of de-identification is not independently verified in the policy text, and re-identification risks exist particularly with detailed financial behavioral data.
Your trading behavior and account activity may inform research and marketing products shared with third parties after being aggregated or de-identified. The policy does not specify the de-identification standard applied, so users cannot independently assess the re-identification risk.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Public.com.