StockX · StockX Privacy Policy · View original document ↗

Cross-Border Data Transfer to the United States

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time StockX changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity StockX recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for StockX Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that personal data collected from all users will be processed in the United States, and that for EEA and UK users, transfers rely on European Commission Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms under applicable law.

This analysis describes what StockX's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that all user data is processed in the United States and discloses that EEA and UK transfers rely on Standard Contractual Clauses or equivalent mechanisms. Compliance teams should verify that the SCCs in use reflect current post-Schrems II requirements and that supplementary measures are implemented where the legal framework of the recipient country requires evaluation.

Interpretive note: The specific SCC module versions and supplementary measures in use are not specified in the policy, limiting the ability to assess the completeness of the disclosed transfer safeguards.

Recent Activity

This document changed recently

Medium Jul 9, 2026

The updated policy authorizes StockX to share and sell personal information to a broader range of recipients than previously disclosed. Specifically, the policy now explicitly permits sharing or selling personal data, including identifiers, transaction data, and browsing behavior, to Live Sellers on the Live Shopping Platform, Sellers on the Listings Marketplace, and third-party data brokers. The prior version limited disclosures to 'sharing' with 'StockX Verified Sellers' without explicit reference to data sales or data brokers. Under the revised terms, data sale and sharing is now standard practice for analytics, advertising, and marketplace partners. The policy does not describe a consumer opt-out mechanism for this data sharing or selling.

View change record →

Consumer impact (what this means for users)

The agreement states that personal data will be processed in the United States regardless of the user's country of residence, and that EEA and UK users' data transfers are governed by Standard Contractual Clauses or equivalent legal mechanisms. The policy acknowledges that US data protection laws may differ from laws in users' countries of residence.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Contact StockX at dpo@stockx.com to request a copy of the safeguards used to transfer your personal data outside your jurisdiction, as offered in the policy.

Cross-platform context

See how other platforms handle Cross-Border Data Transfer to the United States and similar clauses.

Compare across platforms →

Monitoring

StockX has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Please be aware that information we obtain about you will be processed in the United States by StockX or our service providers or affiliates. StockX has its headquarters in the United States. Information we collect about you will be processed in the United States and depending upon the nature of your interaction with us, may be further processed in other countries. By using the Site or our Services, you acknowledge your Personal Information may be transferred to and processed in jurisdictions outside your own as described in this Privacy Policy. Please be aware that the data protection laws and regulations that apply to your Personal Information transferred to the United States or other jurisdictions may be different from the laws in your country of residence. The United States may not afford the same level of protection as laws in your own country. If you are located in the EEA or the UK, we will transfer Personal Information to countries for which adequacy decisions have been issued, use contractual protections for the transfer of Personal Information to third parties, such as the European Commission's Standard Contractual Clauses or their equivalent under applicable law, or rely on other data transfer mechanisms where applicable.

Excerpt from StockX's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V governing international data transfers for EEA users and the UK GDPR for UK users. The EU-US Data Privacy Framework adequacy decision, where applicable, and Standard Contractual Clauses as approved by the European Commission are the primary transfer mechanisms referenced. The UK International Data Transfer Agreement is engaged for UK transfers. Enforcement authorities include EU national supervisory authorities and the UK Information Commissioner's Office. 2) GOVERNANCE EXPOSURE: Medium. The policy references Standard Contractual Clauses and equivalent mechanisms without specifying which module or version is in use, limiting transparency regarding the specific transfer safeguards applied. Compliance teams should confirm that the SCCs currently in use reflect the 2021 European Commission standard contractual clauses and that Transfer Impact Assessments have been conducted for US-based processing. 3) JURISDICTION FLAGS: EEA and UK users face the highest exposure given GDPR and UK GDPR transfer restriction requirements. Users in other jurisdictions with cross-border transfer restrictions, including those governed by the StockX Mexico, South Korea, and Japan sections, should be assessed under their respective local frameworks. 4) CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with US-based service providers and affiliates receiving EEA or UK user data should be reviewed to confirm that appropriate SCCs or equivalent mechanisms are in place and that Transfer Impact Assessments have been documented. The policy's reference to 'other data transfer mechanisms where applicable' should be clarified in vendor agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should maintain a current record of transfer mechanisms in use for each data transfer relationship and ensure that any reliance on adequacy decisions reflects current EU Commission determinations. The policy's offer to provide copies of transfer safeguards upon request should be operationalized through a documented request-response process.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over US-based entities' compliance with cross-border data transfer representations under the FTC Act
    File a complaint →

Provision details

Document information
Document
StockX Privacy Policy
Entity
StockX
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016253
Document ID
CA-D-00734
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
5f972315c3314294a56a18746e81c4d551f0e9d4e19b8710fa0ff79e384791d4
Analysis generated
July 9, 2026 09:57 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: StockX
Document: StockX Privacy Policy
Record ID: CA-P-016253
Captured: 2026-07-09 09:57:04 UTC
SHA-256: 5f972315c3314294…
URL: https://conductatlas.com/platform/stockx/stockx-privacy-policy/provision/CA-P-016253/cross-border-data-transfer-to-the-united-states/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does StockX's Cross-Border Data Transfer to the United States clause do?

This provision establishes that all user data is processed in the United States and discloses that EEA and UK transfers rely on Standard Contractual Clauses or equivalent mechanisms. Compliance teams should verify that the SCCs in use reflect current post-Schrems II requirements and that supplementary measures are implemented where the legal framework of the recipient country requires evaluation.

How does this clause affect you?

The agreement states that personal data will be processed in the United States regardless of the user's country of residence, and that EEA and UK users' data transfers are governed by Standard Contractual Clauses or equivalent legal mechanisms. The policy acknowledges that US data protection laws may differ from laws in users' countries of residence.

Is ConductAtlas affiliated with StockX?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by StockX.