Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
Target's privacy policy describes how Target collects and uses personal information across its stores, website, mobile app, Target Circle loyalty program, Target Plus marketplace, and RedCard financial products. The policy states that Target collects identifiers, payment information, biometric data including face geometry from beauty try-on tools, precise geolocation, browsing activity, purchase history, and inferences about consumer preferences, and authorizes sharing this data with advertising and analytics partners, marketplace sellers, and loyalty program partners. California residents and residents of several other states are granted specific rights to access, correct, delete, or opt out of the sale or sharing of their personal information through mechanisms described in the policy.
This document is Target Corporation's privacy policy governing the collection, use, sharing, and retention of personal information across Target's retail, digital, and loyalty program ecosystems, with stated legal bases including consent, contractual necessity, and compliance with applicable law. The policy states that Target collects identifiers, contact information, payment card data, biometric identifiers (including face geometry data from beauty try-on features), precise geolocation, browsing and search history, purchase history, inferences drawn from personal information, and sensitive personal information such as health-related data; the terms authorize sharing of this data with advertising partners, analytics providers, data brokers operating as service providers, Target Plus marketplace sellers, and loyalty program partners including Ulta Beauty and Marriott. Notably, the policy discloses the collection of biometric identifiers and face geometry data in connection with augmented reality beauty features, which engages state biometric privacy statutes (including the Illinois Biometric Information Privacy Act and similar laws in Texas and Washington) that impose consent, retention, and destruction obligations that may constrain how the terms apply in practice. The policy engages the California Consumer Privacy Act as amended by CPRA, state consumer protection statutes, and the FTC Act; California residents receive enumerated rights including the right to know, correct, delete, opt out of sale or sharing, and limit use of sensitive personal information, while residents of additional states including Colorado, Connecticut, Virginia, and others receive analogous state-law rights under frameworks the policy acknowledges by reference to a state privacy rights table.
The agreement establishes that Target collects a broad range of personal information including biometric identifiers, precise geolocation, inferences about preferences, and sensitive personal information, and authorizes sharing this data with advertising partners, analytics providers, marketplace sellers, and loyalty program partners. Under these terms, consumers who use beauty try-on features provide biometric face geometry data subject to collection and retention practices disclosed in the policy, and consumers who browse or shop without making purchases may still have browsing and inference data collected and shared for advertising purposes. You can opt out of the sale or sharing of your personal information, request deletion of your data, or limit the use of sensitive personal information through the privacy rights tools available at Target's privacy request portal or by calling 1-800-440-0680.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
53 important changes detected
64 versions captured · Last updated: July 2026
The provided diff data appears to contain minified JavaScript code and website structure markup rather than readable privacy policy language. The change detection system flagged 4 modified sentences within a …
View change record →The change detected in Target's privacy policy on July 17, 2026 involves 4 modified sentences in a 313-sentence document. The diff context provided consists of minified JavaScript code and HTML …
View change record →The change detected in Target's Privacy Policy on July 16, 2026 involved modifications to 5 sentences within the policy document. The available diff context shows HTML and minified JavaScript content …
View change record →The provided diff contains only minified JavaScript code and HTML markup fragments that do not represent substantive policy language changes. The capture method appears to have extracted obfuscated technical implementation …
View change record →A change was detected in Target's privacy policy on July 14, 2026, consisting of 5 modified sentences within a 313-sentence document. The provided diff context shows truncated HTML and JavaScript …
View change record →The change notification indicates that Target's Privacy Policy was updated on July 13, 2026, with 5 sentences modified, but the actual substantive content of those modifications is not visible in …
View change record →The diff provided contains only HTML metadata, JavaScript minified code, and technical infrastructure elements. No substantive privacy policy content changes are visible in the provided diff excerpt. The change summary …
View change record →The provided diff context shows only HTML and JavaScript markup fragments and does not contain readable privacy policy language changes. The detection indicates 5 sentences were modified within a 313-sentence …
View change record →The Target Privacy Policy was updated on July 9, 2026. The diff shows the document was regenerated or reprocessed, but the actual substantive privacy language changes are not clearly visible …
View change record →The detected change involves modifications to Target's website HTML and JavaScript configuration files rather than substantive updates to the Privacy Policy document itself. The diff shows changes to CSS stylesheet …
View change record →Target's Privacy Policy was updated on July 7, 2026, with 5 sentences modified across the document. The change detection captured modifications to the policy structure but the diff context provided …
View change record →The provided diff context appears to be technical HTML and JavaScript code from Target's website rather than substantive privacy policy text. The diff shows website infrastructure and page layout changes, …
View change record →The provided diff context appears to be HTML and JavaScript code from Target's website landing page rather than actual privacy policy text changes. The detected change claims 4 sentences were …
View change record →The provided diff context contains primarily technical HTML and JavaScript code from Target's website infrastructure rather than substantive privacy policy content changes. The BEFORE and AFTER sections show identical core …
View change record →Target's privacy policy page was updated on July 3, 2026, but the provided HTML diff shows only technical asset and script changes, CSS file references, and cached query data updates …
View change record →Target updated its Privacy Policy on July 2, 2026, with 5 sentences modified across 313 total sentences in the document. The DIFF context provided consists of HTML markup, JavaScript configuration, …
View change record →Target's Privacy Policy was updated on July 1, 2026. The change involved modifications to 5 sentences across the policy document, which now contains 313 total sentences. The specific substantive changes …
View change record →Target's Privacy Policy page on its website was updated on June 30, 2026, with minor technical modifications to the underlying HTML, CSS, and JavaScript infrastructure. Five sentences were modified within …
View change record →The provided diff context contains HTML/JavaScript markup rather than actual privacy policy text changes. The detected change notes that 4 sentences were modified in Target's Privacy Policy, updated on June …
View change record →Target's Privacy Policy webpage was updated on June 28, 2026. The change appears to be primarily technical and formatting-related, affecting the HTML structure and asset loading of the page rather …
View change record →Target's Privacy Policy webpage was updated on June 26, 2026. The change detection identified 5 sentences modified in the document, which now contains 313 total sentences. The specific content changes …
View change record →Target's privacy policy was updated on June 25, 2026. The change detection shows 4 sentence modifications in a 313-sentence document, but the diff context provided consists almost entirely of unrelated …
View change record →Target updated its privacy policy landing page and global navigation banners. The change involves technical updates to the HTML document structure, including modifications to feature flag configurations, webpack bundle identifiers, …
View change record →The detected change involved modifications to 5 sentences in Target's privacy policy document structure, captured on June 23, 2026. The core policy content appears substantively unchanged based on the provided …
View change record →Target updated its Privacy Policy on June 22, 2026. Five sentences were modified in the document, which now contains 313 sentences. The change detection system identified modifications to the policy …
View change record →Target's Privacy Policy webpage was updated on June 22, 2026. The detected changes involve modifications to 5 sentences within the policy document, which now contains 313 total sentences. The changes …
View change record →Target updated its Target Privacy Policy on June 21, 2026. The change involved 5 sentence modifications within the 313-sentence document. The document continues to describe how Target collects, uses, shares, …
View change record →The DIFF data provided is HTML/JavaScript infrastructure code rather than privacy policy text. The document structure shows Target's privacy policy page framework was updated between June 15, 2026 and June …
View change record →Target modified five sentences in its privacy policy on June 19, 2026. The specific substantive changes to the policy language are not fully visible in the provided diff excerpt, which …
View change record →Target updated its privacy policy on June 18, 2026. The change detection indicates 5 sentences were modified within the full policy document, but the diff context provided consists primarily of …
View change record →The diff provided consists of minified JavaScript code and HTML markup with no substantive changes to the actual privacy policy content visible in the truncated sections. The change detection system …
View change record →The provided diff context shows technical HTML and JavaScript code fragments that do not contain substantive privacy policy language changes. The detected change summary indicates 5 sentences were modified within …
View change record →Target updated its Privacy Policy on June 15, 2026, making 7 sentence-level modifications across 313 total sentences. The specific changes detected in the provided diff involve updated links to state-specific …
View change record →Target's privacy policy page was updated on June 16, 2026, but the provided diff consists primarily of HTML markup and JavaScript configuration changes rather than substantive policy language changes. The …
View change record →Target updated its Privacy Policy on June 15, 2026. The change involved modifications to 21 sentences across the document, including updated metadata timestamps and component identifiers in the HTML markup. …
View change record →The change detected in Target's privacy policy on June 15, 2026 appears to involve only formatting and markup adjustments in the document source code. The before and after versions contain …
View change record →The provided diff content appears to be technical JavaScript code and website navigation elements rather than substantive privacy policy language. The detected change notification indicates 4 sentences were modified within …
View change record →The diff provided consists almost entirely of HTML markup, minified JavaScript, and encoded HTML entities that appear to be structural or technical updates to how the Target Privacy Policy is …
View change record →The change detected in Target's privacy policy document appears to be a removal of a prehydration script element (`<script id="beacon-prehydration">`) that was present in the before version but absent in …
View change record →Target added a new beacon tracking script to its website that fires on page prehydration, based on the insertion of a `<script id="beacon-prehydration">` tag that calls `/api/beacon/top-of-funnel?beaconType=prehydration&formFactor=desktop`. This technical change …
View change record →The change detected in Target's privacy policy involves technical updates to the website backend, including modified CSS stylesheets and JavaScript bundle hashes. The actual policy content remains substantively the same …
View change record →The captured document is a web page snapshot showing Target's Privacy Policy landing page with no substantive policy language changes detected between the two HTML versions. The change metadata indicates …
View change record →The change detected involves modifications to Target's privacy policy page HTML and associated server-side rendering data captured on June 11, 2026. The diff shows updates to backend configuration variables (geographic …
View change record →This change involves modifications to four sentences in Target's Privacy Policy published on June 10, 2026. The diff context provided consists primarily of HTML markup and JavaScript code rather than …
View change record →The detected change is within the HTML/web framework code that serves Target's privacy policy page, not within the privacy policy document itself. The diff shows changes to server-side location variables …
View change record →Target's privacy policy was substantially reformatted on June 10, 2026, with 136 sentences added, 114 removed, and 120 modified, resulting in a 313-sentence document. The underlying data categories, collection methods, …
View change record →Target updated its privacy policy on May 16, 2026, by modifying footer navigation and promotional content. The previous version included links to 'Gift Ideas for Mom', 'Last update: March 5, …
View change record →Target's privacy policy was updated on May 2, 2026 with minor editorial changes: one sentence was removed and one sentence was modified. The document now contains 290 sentences. Based on …
View change record →Target's privacy policy was updated on April 1, 2026, but the detected change appears to be a formatting or navigation element addition rather than a substantive policy modification. The update …
View change record →Target's privacy policy update on March 20, 2026 involved removing a line of unrelated marketing content (Easter, Gift Ideas, Deals promotions) and modifying how sponsored content appears in the document. …
View change record →Target's privacy policy was updated on March 19, 2026 with minor editorial changes to the policy interface. One sentence was removed from a 'Loading' placeholder section, and new content describing …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Target has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle AI Model Development and Training Using Data and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.