Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that SHEIN hashes and uploads customer email addresses to third-party platforms to generate lookalike advertising audiences, with the uploaded list deleted after comparison.
This analysis describes what Shein's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes the transmission of hashed customer email addresses to third-party advertising platforms for lookalike audience generation, which may engage state privacy law requirements for disclosure of data sharing for advertising purposes and potentially COPPA considerations if any hashed addresses belong to minors.
Previously, Shein asked users to explicitly agree or disagree with account persistence for future logins. The updated terms remove this choice entirely. Instead of a consent decision, users now see a promotional discount offer in that location. This means users lose direct control over whether Shein maintains their login session across device visits, which affects convenience and privacy preferences around authentication persistence.
View change record →New disclosure of email-based lookalike audience creation using hashed data shared with third-party advertising platforms, enabling targeted advertising based on user similarity.
View full change record →Under this provision, customer email addresses are hashed and transmitted to third-party advertising platforms such as Meta to generate audiences of users with similar characteristics. The agreement states that the uploaded list is deleted after the lookalike audience is generated and that SHEIN does not receive the identities of matched individuals unless they interact with an advertisement.
Cross-platform context
See how other platforms handle Lookalike Audience Hashing for Advertising and similar clauses.
Compare across platforms →Monitoring
Shein has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may also show ads to audiences that share similar characteristics as you. To do so, a list of email addresses is irreversibly encrypted through hashing and uploaded or transmitted from our site, and the hashed data is compared against the third party's own users, generating a 'lookalike audience' of matching addresses and deleting the uploaded list. We do not have access to the identity of any person in the 'lookalike' audience unless they choose to click on one of our advertisements.Excerpt from Shein's Terms and Conditions
1. REGULATORY LANDSCAPE: This provision engages the CCPA and CPRA disclosure requirements for sharing personal information with advertising platforms, as well as FTC guidance on the use of customer data in digital advertising. Meta's Custom Audiences product and similar tools have been subject to regulatory scrutiny in multiple jurisdictions. Where hashed email addresses belong to minors, COPPA may impose additional restrictions on transmission to third-party advertising platforms. 2. GOVERNANCE EXPOSURE: Medium. The hashing and transmission of customer email addresses to third-party advertising platforms constitutes sharing of personal information under CCPA and CPRA, and must be disclosed and subject to opt-out. The policy provides an opt-out via the site footer link, though compliance teams should verify that the opt-out mechanism operationally prevents email hashing and transmission for opted-out users. 3. JURISDICTION FLAGS: California's CPRA requires disclosure of categories of personal information shared for cross-context behavioral advertising. EU GDPR would require a lawful basis assessment for hashing and transmitting email addresses of EU residents to third-party platforms, as this constitutes processing of personal data. Illinois BIPA does not directly apply to email hashing, though any biometric component would require separate analysis. 4. CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with advertising platforms receiving hashed email data should be reviewed to confirm use limitations, deletion obligations upon comparison completion, and prohibitions on reconstitution or independent use of hashed data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit the technical implementation of the lookalike audience process to confirm that hashed email transmission is suppressed for users who have exercised the opt-out right, and that consent records for email addresses transmitted to advertising platforms are maintained in a manner consistent with applicable state and federal requirements.
This provision authorizes the transmission of hashed customer email addresses to third-party advertising platforms for lookalike audience generation, which may engage state privacy law requirements for disclosure of data sharing for advertising purposes and potentially COPPA considerations if any hashed addresses belong to minors.
Under this provision, customer email addresses are hashed and transmitted to third-party advertising platforms such as Meta to generate audiences of users with similar characteristics. The agreement states that the uploaded list is deleted after the lookalike audience is generated and that SHEIN does not receive the identities of matched individuals unless they interact with an advertisement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shein.