Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
By ordering Third-Party Offerings through the Marketplace, users authorize Vendors to access, transmit, modify, delete, or store data on Vendor or third-party systems. RunPod disclaims all responsibility for Vendor data security, privacy practices, and data use, placing sole responsibility on the user for authorizing Vendor data access.
This analysis describes what RunPod's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that Third-Party Vendor data practices fall entirely outside RunPod's contractual responsibility. Enterprise customers integrating Marketplace third-party software with data stored on RunPod infrastructure must conduct independent vendor due diligence, as RunPod provides no contractual protection regarding Vendor data handling.
The updated Terms of Service remove previous promotional language including referral bonuses (previously described as $5-$500 random credit bonuses) and product feature descriptions. The revised document now explicitly states it is a legally binding agreement between you and RunPod, Inc., with a last-updated date of March 24, 2026. No new restrictions or obligations are introduced by this change; the restructuring primarily formalizes the legal framework and eliminates marketing content that previously appeared within the terms document.
View change record →Under this clause, enabling any Third-Party Marketplace Offering authorizes that Vendor to access, transmit, modify, or store user data, and RunPod's contractual responsibility for that data ends at the point of Vendor access. Users bear sole responsibility for evaluating Vendor Terms and security practices before enabling integrations.
Cross-platform context
See how other platforms handle Third-Party Vendor Data Disclaimer and similar clauses.
Compare across platforms →Monitoring
RunPod has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you place an Order for Third-Party Offerings, you authorize Vendors to access or use certain data in the applicable Service. This may include transmitting, transferring, modifying or deleting such data, or storing such data on Vendor or third-party systems. Any third-party Vendor's use of accessed data (whether data in the Service or separately collected from you or your device) is subject to the applicable Vendor Terms. Runpod is not responsible for any access, use, transfer or security of data or information by third-party Vendors or by Third-Party Offerings, or for the security or privacy practices of any third-party Vendor, Third-Party Offering or their processors. You are solely responsible for your decision to permit any third-party Vendor or Third-Party Offering to access or use data to which you've granted access.Excerpt from RunPod's Terms of Service
REGULATORY LANDSCAPE: This provision interacts directly with GDPR obligations for data controllers who engage processors or sub-processors, as any data transferred to a Third-Party Vendor may require a Data Processing Agreement under GDPR. The disclaimer of RunPod's responsibility for Vendor data practices does not relieve users of their own obligations as data controllers under GDPR or CCPA to ensure adequate safeguards for personal data shared with third parties. HIPAA-covered entities should assess whether any Third-Party Vendor qualifies as a Business Associate requiring a BAA. GOVERNANCE EXPOSURE: High for enterprise customers processing personal, health, or financial data on RunPod infrastructure who also use Marketplace integrations. The disclaimer transfers all compliance risk for Vendor data practices to the user, including risks from Vendor data breaches, cross-border transfers, or unauthorized secondary use. JURISDICTION FLAGS: EU/EEA customers face the most significant exposure, as GDPR requires documented legal bases for data transfers to third parties and adequate safeguards for international transfers. California customers should assess whether Third-Party Vendor access constitutes a data sale or sharing arrangement under CCPA. Illinois BIPA may be relevant if biometric data is stored on RunPod and accessed by Third-Party Vendors. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should conduct independent security assessments of any Third-Party Marketplace Vendor before enabling data access. Existing vendor management frameworks should be extended to cover RunPod Marketplace third parties. DPAs or BAAs may need to be executed directly with Third-Party Vendors rather than through RunPod. The clause also discloses that Vendors receive user identity information including name, company name, addresses, email, and phone number upon order completion. COMPLIANCE CONSIDERATIONS: Legal teams should inventory all Third-Party Offerings enabled through the RunPod Marketplace and assess each Vendor's data practices independently. Data protection impact assessments may be required for integrations involving personal or sensitive data. The user's consent mechanism for Vendor data access should be documented as part of any GDPR compliance program. Incident response plans should account for the possibility of Vendor-side data breaches for which RunPod will not provide notification.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision discloses that Third-Party Vendor data practices fall entirely outside RunPod's contractual responsibility. Enterprise customers integrating Marketplace third-party software with data stored on RunPod infrastructure must conduct independent vendor due diligence, as RunPod provides no contractual protection regarding Vendor data handling.
Under this clause, enabling any Third-Party Marketplace Offering authorizes that Vendor to access, transmit, modify, or store user data, and RunPod's contractual responsibility for that data ends at the point of Vendor access. Users bear sole responsibility for evaluating Vendor Terms and security practices before enabling integrations.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by RunPod.