Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that SHEIN shares device identifiers, cookies, and behavioral inferences with partners, third parties, and affiliates for analytics and targeted advertising, and acknowledges that such sharing may be interpreted as a sale or sharing of personal information under applicable state privacy laws.
This analysis describes what Shein's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that device identifiers and behavioral inferences have been shared with advertising and analytics partners in a manner that may trigger opt-out rights under CCPA, CPRA, and similar state privacy statutes, and provides an opt-out mechanism via the site footer link and app settings.
Previously, Shein asked users to explicitly agree or disagree with account persistence for future logins. The updated terms remove this choice entirely. Instead of a consent decision, users now see a promotional discount offer in that location. This means users lose direct control over whether Shein maintains their login session across device visits, which affects convenience and privacy preferences around authentication persistence.
View change record →Under this clause, behavioral inferences and device identifiers collected from site and app visits may be shared with third-party advertising and analytics partners. The agreement provides an opt-out mechanism accessible through the 'Do Not Sell or Share My Personal Information' or 'Manage Cookies' link in the site footer or app settings menu.
Cross-platform context
See how other platforms handle Targeted Advertising and Sale or Sharing Disclosure and similar clauses.
Compare across platforms →Monitoring
Shein has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We do not sell our users' information to third parties as that term is generally understood. However, making certain identifiers available to third parties may be considered a 'sale' or 'sharing' under certain laws. When you visit our website, we may share some personal identifiers such as cookies and other tracking technologies for analytics and to personalize your experience with targeted ads as described herein. In the previous 12 months, we may have shared identifiers and inferences about you with our partners, third parties, and affiliates in such a way that, under such privacy laws, may be interpreted as 'selling' or 'sharing'.Excerpt from Shein's Terms and Conditions
1. REGULATORY LANDSCAPE: This provision directly engages the CCPA and CPRA, which require businesses that sell or share personal information for cross-context behavioral advertising to provide a clear opt-out mechanism and disclose the categories of information shared. Similar requirements apply under Colorado, Connecticut, Virginia, Texas, and other state privacy statutes. The California Privacy Protection Agency and California AG hold primary enforcement authority under the CPRA. The FTC's guidance on digital advertising data practices is also relevant. 2. GOVERNANCE EXPOSURE: High. The acknowledgment that sharing of identifiers and inferences may be interpreted as a sale or sharing under applicable state law requires operational compliance with opt-out mechanisms, do-not-sell signal processing, and Global Privacy Control response requirements under the CPRA. The document does not specify whether SHEIN processes Global Privacy Control signals, which is an enforceable requirement under California regulations. 3. JURISDICTION FLAGS: California creates the highest compliance exposure given CPRA enforcement authority and specific technical requirements for opt-out signal processing. Colorado's privacy statute requires recognition of universal opt-out mechanisms. Virginia, Texas, Connecticut, and other state statutes require consumer opt-out rights for targeted advertising. EU GDPR consent requirements apply to any EU resident data used for behavioral advertising. 4. CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with advertising and analytics partners should be reviewed to confirm that their use of shared identifiers and inferences is limited to disclosed purposes and that they are contractually prohibited from onward sale or sharing without appropriate authorization. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a consent mechanism audit to verify that the footer opt-out link and app settings menu function correctly and process opt-out requests in a manner consistent with CPRA and applicable state statute requirements. The policy should be assessed for whether it adequately discloses each category of personal information shared for targeted advertising and the identity or category of each third-party recipient, as required by state law.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that device identifiers and behavioral inferences have been shared with advertising and analytics partners in a manner that may trigger opt-out rights under CCPA, CPRA, and similar state privacy statutes, and provides an opt-out mechanism via the site footer link and app settings.
Under this clause, behavioral inferences and device identifiers collected from site and app visits may be shared with third-party advertising and analytics partners. The agreement provides an opt-out mechanism accessible through the 'Do Not Sell or Share My Personal Information' or 'Manage Cookies' link in the site footer or app settings menu.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shein.