SoFi · SoFi Privacy Notice · View original document ↗

Targeting Cookies and Cross-Site Profiling

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time SoFi changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity SoFi recorded 12 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for SoFi Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that targeting cookies collect user interaction data across websites to build interest-based profiles, which are used for personalized advertising and may be shared with third-party advertisers for ad performance measurement and profile-based ad delivery.

This analysis describes what SoFi's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision describes cross-context behavioral advertising practices involving profile construction from cross-site tracking data and sharing of that data with third-party advertisers. These practices fall within the categories of data use subject to opt-out rights under CCPA/CPRA and may engage FTC guidance on online behavioral advertising.

Recent Activity

This document changed recently

Medium Jun 15, 2026

The updated terms restructure how SoFi discloses and collects consent for tracking technologies. Previously, SoFi stated that non-selection of preferences constituted acceptance of tracking. The updated version creates distinct cookie categories (Functional, Performance, Targeting, Strictly Necessary) and establishes a Privacy Preference Center allowing you to individually toggle Performance and Targeting cookies on or off. Strictly Necessary Cookies remain non-optional and cannot be disabled, as the updated terms state these are necessary for website functionality. You can manage individual cookie category preferences through the Privacy Preference Center interface before or after initial site visit.

View change record →
Medium Jun 12, 2026

The updated Privacy Notice explicitly discloses that SoFi collects user information through cookies, pixels, and other tracking technologies and shares this data with social media, advertising, and analytics partners. Previously, the policy described these practices in more general language. Under the revised terms, continued use of SoFi's website constitutes acceptance of these tracking and data-sharing practices unless the user actively makes selections in the Privacy Preference Center. You can use the preference center to opt out of optional tracking technologies, though strictly necessary cookies cannot be disabled.

View change record →
Medium Jun 2, 2026

The updated privacy notice explicitly discloses that SoFi uses pixels and tracking technologies to collect information about your actions and preferences, and shares this data with social media, advertising, and analytics partners. The revised consent interface distinguishes between strictly necessary cookies (which cannot be disabled) and optional cookies for performance and targeting purposes (which require affirmative consent). The terms state that if you do not make a selection, you agree to use of these technologies; you can opt out by toggling the button that appears to the right of each optional cookie category.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, the agreement authorizes the use of targeting cookies to track user behavior across websites, build interest profiles, and share that data with advertisers for personalized ad delivery and performance measurement. Users who activate the targeting cookie opt-out in SoFi's Privacy Preference Center can decline this category of data collection and sharing.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Open SoFi's Privacy Preference Center via the cookie consent banner or the 'Your privacy options' footer link. Toggle the 'Targeting Cookies' switch to the off position and save your preferences.

Cross-platform context

See how other platforms handle Targeting Cookies and Cross-Site Profiling and similar clauses.

Compare across platforms →

Monitoring

SoFi has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Targeting cookies track users' actions and are used to identify users between different websites. Targeting cookies collect user information and use it to build a profile of users' interests and then show personalized ads for that specific user. Targeting cookies help to attract customers with targeted ads. The information the cookies gather about you can be shared with other advertisers to measure the performance of their advertisements and may be used to build a profile to deliver personalized ads.

Excerpt from SoFi's Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages CCPA/CPRA provisions governing cross-context behavioral advertising and the sell/share opt-out obligations for businesses that share personal information with third parties for advertising purposes. The FTC's guidance on online behavioral advertising, including principles for transparency and consumer control, is also relevant. The California Privacy Protection Agency and California Attorney General hold enforcement authority. State privacy laws in other jurisdictions with similar behavioral advertising opt-out requirements may also apply. 2) GOVERNANCE EXPOSURE: Medium. The disclosure that targeting cookie data may be shared with advertisers for profile construction and ad performance measurement describes practices that are subject to opt-out requirements under CCPA/CPRA. The adequacy of the opt-out mechanism and whether it effectively prevents all described sharing upon activation are operational compliance questions that require technical audit. 3) JURISDICTION FLAGS: California residents have clear statutory opt-out rights for cross-context behavioral advertising under CCPA/CPRA. Residents of other states with enacted comprehensive privacy laws may have similar rights. Users in EU/EEA jurisdictions would be subject to GDPR consent requirements for this category of processing, though the document appears scoped to U.S. users and does not address GDPR applicability. 4) CONTRACT AND VENDOR IMPLICATIONS: Sharing targeting cookie data with third-party advertisers creates vendor contract review obligations to confirm that data use restrictions are contractually established and enforced. The disclosure that shared data may be used by other advertisers to build profiles raises questions about secondary use restrictions in third-party agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit the technical implementation of the targeting cookie opt-out to confirm it prevents both data collection and downstream sharing upon activation. The list of advertisers and analytics partners receiving this data should be maintained in an updated data map and disclosed in the full Online Privacy Policy. Global Privacy Control signal recognition should be assessed for California compliance.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC holds enforcement authority over unfair or deceptive practices in online behavioral advertising and cross-site tracking disclosures
    File a complaint →
  • State AG
    California's Attorney General holds enforcement authority over CCPA/CPRA cross-context behavioral advertising opt-out requirements applicable to this provision
    File a complaint →

Provision details

Document information
Document
SoFi Privacy Notice
Entity
SoFi
Document last updated
March 14, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013776
Document ID
CA-D-00104
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7b76847eebe703a2aa3f0e1fafc55926e9cbe3cb44aae8c482b48b4f2e87ebe4
Analysis generated
July 9, 2026 03:58 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: SoFi
Document: SoFi Privacy Notice
Record ID: CA-P-013776
Captured: 2026-07-09 03:58:12 UTC
SHA-256: 7b76847eebe703a2…
URL: https://conductatlas.com/platform/sofi/sofi-privacy-notice/provision/CA-P-013776/targeting-cookies-and-cross-site-profiling/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does SoFi's Targeting Cookies and Cross-Site Profiling clause do?

This provision describes cross-context behavioral advertising practices involving profile construction from cross-site tracking data and sharing of that data with third-party advertisers. These practices fall within the categories of data use subject to opt-out rights under CCPA/CPRA and may engage FTC guidance on online behavioral advertising.

How does this clause affect you?

Under this clause, the agreement authorizes the use of targeting cookies to track user behavior across websites, build interest profiles, and share that data with advertisers for personalized ad delivery and performance measurement. Users who activate the targeting cookie opt-out in SoFi's Privacy Preference Center can decline this category of data collection and sharing.

Is ConductAtlas affiliated with SoFi?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by SoFi.