10 Total
1 High severity
7 Medium severity
2 Low severity
Summary

This document establishes Spotify's data collection and usage practices for U.S. users of its music and podcast streaming services. Spotify collects streaming history, search queries, device identifiers, inferred interests, AI feature prompts and transcripts, and facial photographs for age verification purposes, with authorization to share this data with advertising partners and analytics providers for tailored advertising. Users may disable tailored advertising through the 'Tailored Ads' setting at spotify.com/account/privacy and may request data download or deletion through the 'Download your data' tool on the same page.

Technical / Legal Breakdown

This document is Spotify USA Inc.'s Privacy Policy, effective 13 April 2026, governing the collection, use, and disclosure of personal data of U.S. residents across all Spotify streaming services, websites, customer service, and community platforms, with legal basis grounded in service provision, consent, legitimate interests, and compliance with applicable law. The policy states Spotify collects User Data (name, email, date of birth, gender, phone number, street address), Usage Data (search queries, streaming history, browsing history, AI feature prompts and transcripts, device identifiers, IP addresses, inferred interests), Voice Data, Payment and Purchase Data, and Age Check Data including biometric facial imagery; the terms authorize sharing this data with advertising partners, analytics providers, payment processors, technical service partners, and other Spotify group companies. The policy asserts an opt-out model for tailored advertising (rather than opt-in), extends state-law privacy rights to all U.S. residents regardless of state, and discloses collection of AI interaction transcripts and facial age estimation data processed by third-party providers, with Age Check Data stated to be deleted immediately after use. The policy engages the California Consumer Privacy Act (CCPA) and its amendments under CPRA, with a separate California Notice at Collection referenced, as well as Virginia, Colorado, Connecticut, and other state comprehensive privacy laws applicable to U.S. residents; the extension of state rights to all U.S. users reduces but does not eliminate jurisdiction-specific compliance exposure. Material compliance considerations include the biometric data dimension of facial age estimation under state biometric laws such as Illinois BIPA, the adequacy of consent mechanisms for AI feature data processing, and the scope of third-party advertising data flows relative to CCPA's sale and sharing definitions.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 7 provisions
Low — 2 provisions

Monitoring

Spotify has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Biometric Age Check Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
COPPA
United States Federal
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:03 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000036
Version ID CA-V-000646
SHA-256 db254b83bbbf7d4b7a71ab2a5e1804fc61607128e1ab37f2ec82555179b63271
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans