When you build and run your own apps using Vercel, Vercel acts as a processor of your users' data, not the controller, meaning you as the developer are responsible for your users' privacy rights in that context.
This analysis describes what Vercel AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Developers deploying applications on Vercel need to understand that they, not Vercel, are legally responsible for their end users' data under GDPR and similar laws, and they must have their own privacy notices and legal bases for processing.
The updated policy establishes a new mechanism for resolving privacy disputes related to Data Privacy Framework transfers. Users in the EU, UK, and EEA who have unresolved privacy complaints can now submit them to VeraSafe for independent review, which will be conducted free of charge. Additionally, the policy introduces an explicit Right to Restriction, permitting users to request that Vercel limit processing of their personal information or restrict further disclosures in certain instances, particularly for sensitive information. You can file a complaint with VeraSafe by submitting required information at https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.
View change record →End users of applications hosted on Vercel should know their privacy rights in that context are determined by the developer who built the application, not by Vercel's privacy policy, meaning Vercel's policy does not directly protect them in that scenario.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"When you use our Services to build and run your own applications, we act as a data processor on your behalf with respect to any personal information you collect and process using our Services. In these circumstances, you are the data controller.Excerpt from Vercel AI's SDK Privacy
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Article 4(7) and Article 4(8) definitions of controller and processor, and Article 28 requirements for data processing agreements between controllers and processors.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Developers deploying applications on Vercel need to understand that they, not Vercel, are legally responsible for their end users' data under GDPR and similar laws, and they must have their own privacy notices and legal bases for processing.
End users of applications hosted on Vercel should know their privacy rights in that context are determined by the developer who built the application, not by Vercel's privacy policy, meaning Vercel's policy does not directly protect them in that scenario.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Vercel AI.