Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data collected from all users will be processed in the United States, and that for EEA and UK users, transfers rely on European Commission Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms under applicable law.
This analysis describes what StockX's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that all user data is processed in the United States and discloses that EEA and UK transfers rely on Standard Contractual Clauses or equivalent mechanisms. Compliance teams should verify that the SCCs in use reflect current post-Schrems II requirements and that supplementary measures are implemented where the legal framework of the recipient country requires evaluation.
Interpretive note: The specific SCC module versions and supplementary measures in use are not specified in the policy, limiting the ability to assess the completeness of the disclosed transfer safeguards.
The updated policy authorizes StockX to share and sell personal information to a broader range of recipients than previously disclosed. Specifically, the policy now explicitly permits sharing or selling personal data, including identifiers, transaction data, and browsing behavior, to Live Sellers on the Live Shopping Platform, Sellers on the Listings Marketplace, and third-party data brokers. The prior version limited disclosures to 'sharing' with 'StockX Verified Sellers' without explicit reference to data sales or data brokers. Under the revised terms, data sale and sharing is now standard practice for analytics, advertising, and marketplace partners. The policy does not describe a consumer opt-out mechanism for this data sharing or selling.
View change record →The agreement states that personal data will be processed in the United States regardless of the user's country of residence, and that EEA and UK users' data transfers are governed by Standard Contractual Clauses or equivalent legal mechanisms. The policy acknowledges that US data protection laws may differ from laws in users' countries of residence.
Cross-platform context
See how other platforms handle Cross-Border Data Transfer to the United States and similar clauses.
Compare across platforms →Monitoring
StockX has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Please be aware that information we obtain about you will be processed in the United States by StockX or our service providers or affiliates. StockX has its headquarters in the United States. Information we collect about you will be processed in the United States and depending upon the nature of your interaction with us, may be further processed in other countries. By using the Site or our Services, you acknowledge your Personal Information may be transferred to and processed in jurisdictions outside your own as described in this Privacy Policy. Please be aware that the data protection laws and regulations that apply to your Personal Information transferred to the United States or other jurisdictions may be different from the laws in your country of residence. The United States may not afford the same level of protection as laws in your own country. If you are located in the EEA or the UK, we will transfer Personal Information to countries for which adequacy decisions have been issued, use contractual protections for the transfer of Personal Information to third parties, such as the European Commission's Standard Contractual Clauses or their equivalent under applicable law, or rely on other data transfer mechanisms where applicable.Excerpt from StockX's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V governing international data transfers for EEA users and the UK GDPR for UK users. The EU-US Data Privacy Framework adequacy decision, where applicable, and Standard Contractual Clauses as approved by the European Commission are the primary transfer mechanisms referenced. The UK International Data Transfer Agreement is engaged for UK transfers. Enforcement authorities include EU national supervisory authorities and the UK Information Commissioner's Office. 2) GOVERNANCE EXPOSURE: Medium. The policy references Standard Contractual Clauses and equivalent mechanisms without specifying which module or version is in use, limiting transparency regarding the specific transfer safeguards applied. Compliance teams should confirm that the SCCs currently in use reflect the 2021 European Commission standard contractual clauses and that Transfer Impact Assessments have been conducted for US-based processing. 3) JURISDICTION FLAGS: EEA and UK users face the highest exposure given GDPR and UK GDPR transfer restriction requirements. Users in other jurisdictions with cross-border transfer restrictions, including those governed by the StockX Mexico, South Korea, and Japan sections, should be assessed under their respective local frameworks. 4) CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with US-based service providers and affiliates receiving EEA or UK user data should be reviewed to confirm that appropriate SCCs or equivalent mechanisms are in place and that Transfer Impact Assessments have been documented. The policy's reference to 'other data transfer mechanisms where applicable' should be clarified in vendor agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should maintain a current record of transfer mechanisms in use for each data transfer relationship and ensure that any reliance on adequacy decisions reflects current EU Commission determinations. The policy's offer to provide copies of transfer safeguards upon request should be operationalized through a documented request-response process.
This provision establishes that all user data is processed in the United States and discloses that EEA and UK transfers rely on Standard Contractual Clauses or equivalent mechanisms. Compliance teams should verify that the SCCs in use reflect current post-Schrems II requirements and that supplementary measures are implemented where the legal framework of the recipient country requires evaluation.
The agreement states that personal data will be processed in the United States regardless of the user's country of residence, and that EEA and UK users' data transfers are governed by Standard Contractual Clauses or equivalent legal mechanisms. The policy acknowledges that US data protection laws may differ from laws in users' countries of residence.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by StockX.