The policy states that in the event of a merger, acquisition, or asset sale, user information may be transferred as a business asset to the acquiring or merging entity, subject to any mandatory legal restrictions.
This analysis describes what Ro's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that all collected user data, including sensitive health information, may be transferred to a third party in a business transaction. The policy states compliance with mandatory legal restrictions but does not specify what notice or consent would be provided to users prior to such a transfer.
The updated policy establishes that Ro has enabled contractual settings with certain advertising partners that restrict those partners' use of data to service provision only, meaning those partners may not use the information for their own advertising or profiling purposes. The policy also expands the list of states where Ro does not sell sensitive personal information for tailored advertising, adding New Jersey, New Hampshire, Nebraska, Iowa, and Delaware. For residents of the newly added states and others covered by partner settings, default restrictions on data use may apply even without an explicit opt-out. You can manage advertising preferences through the policy's stated opt-out mechanisms, including the 'Your Privacy Choices' page and Global Privacy Control signals.
View change record →Under these terms, your personal and health information may be transferred to a new entity if Ro is acquired, merges, or sells its assets. The agreement states that applicable legal restrictions on such transfers will be honored but does not specify pre-transfer notice procedures for users.
Cross-platform context
See how other platforms handle Business Transfer Data Sharing and similar clauses.
Compare across platforms →"As we continue to develop our business, we may buy, merge, or partner with other companies. In such transactions, (including in contemplation of such transactions) user information may be among the transferred assets. If a portion or all of our assets are sold or transferred to a third-party, customer information would likely be one of the transferred business assets. If such transfer is subject to additional mandatory restrictions under applicable laws, we will comply with such restrictions.Excerpt from Ro's Privacy Policy
REGULATORY LANDSCAPE: Business transfers involving health data implicate HIPAA's requirements for business associate agreements with successor entities and restrictions on disclosure of protected health information.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that all collected user data, including sensitive health information, may be transferred to a third party in a business transaction. The policy states compliance with mandatory legal restrictions but does not specify what notice or consent would be provided to users prior to such a transfer.
Under these terms, your personal and health information may be transferred to a new entity if Ro is acquired, merges, or sells its assets. The agreement states that applicable legal restrictions on such transfers will be honored but does not specify pre-transfer notice procedures for users.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ro.