Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The CCPA disclosure table states that StockX has collected and shared sensitive personal information including Social Security numbers, VAT identification numbers, tax identification numbers, and government-issued identification numbers with service providers, identity verification providers, business partners, professional advisors, affiliates, and government entities.
This analysis describes what StockX's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that sensitive personal information, including Social Security numbers, is shared with business partners and professional advisors in addition to identity verification and law enforcement contexts. CCPA imposes specific limitations on the use and disclosure of sensitive personal information, and compliance teams should evaluate whether the disclosed sharing practices satisfy CCPA's restrictions on sensitive data processing.
Interpretive note: The policy's assertion that sensitive personal information sharing occurs only when required under CCPA's right-to-limit framework or for legal purposes may not fully align with the breadth of recipients listed in the CCPA disclosure table, creating interpretive uncertainty about the actual scope of sharing.
The updated policy authorizes StockX to share and sell personal information to a broader range of recipients than previously disclosed. Specifically, the policy now explicitly permits sharing or selling personal data, including identifiers, transaction data, and browsing behavior, to Live Sellers on the Live Shopping Platform, Sellers on the Listings Marketplace, and third-party data brokers. The prior version limited disclosures to 'sharing' with 'StockX Verified Sellers' without explicit reference to data sales or data brokers. Under the revised terms, data sale and sharing is now standard practice for analytics, advertising, and marketplace partners. The policy does not describe a consumer opt-out mechanism for this data sharing or selling.
View change record →The agreement states that sensitive personal information including Social Security numbers and government-issued identification numbers has been shared with a defined set of recipients including business partners and professional advisors. Under CCPA, consumers have the right to limit the use and disclosure of sensitive personal information, which the policy acknowledges applies to these data categories.
Cross-platform context
See how other platforms handle Sensitive Personal Information Sharing Including Social Security Numbers and similar clauses.
Compare across platforms →Monitoring
StockX has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Sensitive Personal Information Social Security Number VAT ID tax identification number governmental-issued identification number We only collect and share sensitive personal information such as your social security number to which the right to limit use and disclosure applies under the CCPA or when it is required for legal purposes (such as identity verification and fraud prevention) Yes service providers identity verification service providers security and fraud prevention service providers business partners professional advisors affiliates government entitiesExcerpt from StockX's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly engages CCPA's sensitive personal information framework, which grants consumers the right to limit the use and disclosure of categories including government identification numbers and financial account information. GDPR Article 9 governs special category data for EEA users, though government identification numbers may not fall within GDPR's Article 9 categories depending on jurisdiction-specific interpretation. The California Privacy Protection Agency (CPPA) has primary enforcement authority over CCPA sensitive data provisions. 2) GOVERNANCE EXPOSURE: High. The disclosure that Social Security numbers are shared with business partners and professional advisors, in addition to legally mandated contexts, requires evaluation against CCPA's limitation on sensitive personal information use. The policy's statement that this sharing occurs only when required by CCPA's right to limit or for legal purposes may not fully account for the breadth of recipients listed in the disclosure table. 3) JURISDICTION FLAGS: California residents have the most direct rights under CCPA's sensitive personal information provisions. Users in states with analogous sensitive data frameworks should be evaluated as those state laws develop. Non-US users providing government identification numbers in connection with tax or customs obligations should be assessed under applicable local data protection law. 4) CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with business partners and professional advisors receiving sensitive personal information, including Social Security numbers, should be reviewed to confirm use limitation and deletion obligations. The breadth of recipients listed in the CCPA disclosure table for sensitive personal information should be reconciled with documented business necessity justifications. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data minimization review to confirm that each recipient category listed in the sensitive personal information disclosure table has a documented legal basis and business necessity. Consumer-facing mechanisms for exercising the CCPA right to limit sensitive personal information use should be audited for usability and effectiveness.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision discloses that sensitive personal information, including Social Security numbers, is shared with business partners and professional advisors in addition to identity verification and law enforcement contexts. CCPA imposes specific limitations on the use and disclosure of sensitive personal information, and compliance teams should evaluate whether the disclosed sharing practices satisfy CCPA's restrictions on sensitive data processing.
The agreement states that sensitive personal information including Social Security numbers and government-issued identification numbers has been shared with a defined set of recipients including business partners and professional advisors. Under CCPA, consumers have the right to limit the use and disclosure of sensitive personal information, which the policy acknowledges applies to these data categories.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by StockX.