The policy establishes that Squarespace acts as an independent data controller for End User data it automatically collects (such as IP addresses via cookies) for its own purposes, while the Customer acts as data controller for all other End User data including webform submissions and cookie data collected for Customer purposes. End Users must consult the relevant Customer's privacy policy for information about Customer Controlled Information.
This analysis describes what Squarespace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a layered accountability structure in which End Users of Customer-hosted sites are subject to two separate data controllers with separate privacy policies, and Squarespace's obligations under this policy do not extend to Customer Controlled Information except for limited enforcement and legal compliance purposes.
Interpretive note: Whether Squarespace's independent controller designation for automatically collected End User data creates joint controller obligations under GDPR is a matter of regulatory interpretation and has not been resolved in this document.
Under this clause, End Users visiting Squarespace-hosted sites should review both this policy and the individual Customer's privacy policy to understand the full scope of data collection and processing applicable to them. The agreement establishes that Squarespace's rights and obligations under this policy do not govern Customer-controlled data practices.
Cross-platform context
See how other platforms handle Dual Data Controller Structure for End User Data and similar clauses.
Compare across platforms →""Customer Controlled Information" is personal information for which a Customer acts as the "data controller" (or similar term under applicable law) and determines the purposes and means of processing. This includes any personal information included in the content uploaded by a Customer to our Services for display on their site, a Customer's domain registration contact information and all information about a Customer's End Users (including information provided by an End User to a Customer via a webform on the Customer's site as well as information automatically received (including via cookies or similar tracking technology) when an End User visits the Customer's site). We also act as an independent data controller for personal information relating to End Users which we automatically receive (including via cookies or similar tracking technology) when an End User visits a site hosted on our Services (such as the End User's IP address) when we process it for our own purposes, including to foster the security and integrity of our Services.Excerpt from Squarespace's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision creates a layered accountability structure in which End Users of Customer-hosted sites are subject to two separate data controllers with separate privacy policies, and Squarespace's obligations under this policy do not extend to Customer Controlled Information except for limited enforcement and legal compliance purposes.
Under this clause, End Users visiting Squarespace-hosted sites should review both this policy and the individual Customer's privacy policy to understand the full scope of data collection and processing applicable to them. The agreement establishes that Squarespace's rights and obligations under this policy do not govern Customer-controlled data practices.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Squarespace.