The policy states that Uber retains personal data as long as necessary for stated service purposes and legal obligations, and will delete data upon request unless retention is required for legal, regulatory, safety, or fraud prevention purposes, with Uber determining the applicability of those exceptions.
This analysis describes what Uber's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Uber retains discretion to determine the duration and scope of data retention and to decline deletion requests based on broadly stated exceptions including safety and fraud prevention, which are categories not limited to specific statutory retention obligations.
Interpretive note: The policy does not specify retention periods by data category or enumerate the precise scope of the safety and fraud prevention exceptions, creating ambiguity about when deletion requests will be honored.
Under this clause, Uber retains personal data for self-determined durations across service and legal purposes, and deletion requests may be declined where Uber determines that safety, fraud prevention, legal, or regulatory grounds apply. Users can submit deletion requests through the Uber app or privacy.uber.com, but the outcome depends on Uber's assessment of applicable exceptions.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"Uber retains user data for as long as necessary for the purposes described above, including to provide its services and comply with legal obligations. Users may request deletion of their data at any time. Following a deletion request, Uber deletes data unless it must be retained due to legal, regulatory, safety, fraud prevention, or other grounds consistent with applicable law.Excerpt from Uber's Privacy Notice
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that Uber retains discretion to determine the duration and scope of data retention and to decline deletion requests based on broadly stated exceptions including safety and fraud prevention, which are categories not limited to specific statutory retention obligations.
Under this clause, Uber retains personal data for self-determined durations across service and legal purposes, and deletion requests may be declined where Uber determines that safety, fraud prevention, legal, or regulatory grounds apply. Users can submit deletion requests through the Uber app or privacy.uber.com, but the outcome depends on Uber's assessment of applicable exceptions.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Uber.