10 Total
0 High severity
8 Medium severity
2 Low severity
Summary

This is Smartsheet's privacy policy, explaining how the project management platform collects and uses personal data about people who visit its website, sign up for a free trial, or use its services. The most important thing to know is that Smartsheet shares your personal data including name, email, usage behavior, and device information with advertising and analytics partners, and may use certain service data to improve AI features. California residents and EU/UK users have specific rights to access, delete, or opt out of certain data uses, which they can exercise by submitting a request through Smartsheet's privacy request form.

Technical / Legal Breakdown

This document is the Smartsheet Privacy Notice, governing how Smartsheet Inc. collects, uses, and shares personal data across its website (smartsheet.com) and related services, with stated legal bases including contract performance, legitimate interests, consent, and legal obligation depending on jurisdiction. The notice states that Smartsheet collects personal data including identifiers, usage data, device information, location data, and customer-submitted content, and authorizes use of that data for product delivery, marketing, analytics, fraud prevention, and AI-related product improvement; it also discloses sharing with third-party service providers, advertising partners, analytics vendors, and business transferees. Notably, the notice distinguishes between Smartsheet's role as a data controller (for website and marketing data) and a data processor (for customer-submitted service data governed by separate customer agreements), a distinction that materially affects what rights individual users can exercise directly against Smartsheet. The notice expressly addresses GDPR obligations for EEA and UK residents, CCPA/CPRA rights for California residents, and references adequacy decisions and Standard Contractual Clauses as international transfer mechanisms; applicability of specific rights depends on jurisdiction and user classification. Compliance teams should note that AI feature data use, third-party advertising integrations, and the controller-processor distinction each create distinct regulatory evaluation points under GDPR, CCPA/CPRA, and potentially the EU AI Act.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 8 provisions
Low — 2 provisions

Monitoring

Smartsheet has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Controller vs. Processor Bifurcation and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:39 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000712
Version ID CA-V-001345
SHA-256 3cb752c502db079d64fe378b27ef5bc2d5e654a7d11a6a9921d969ed218709df
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans