Provision record
Webull · Webull Privacy Policy · View original document ↗

Third-Party Data Sharing with Service Providers and Payment Processors

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Webull changes these terms. Follow Webull →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Webull recorded 6 documented changes in the last 30 days.
Follow Webull →
Monitor governance changes for Webull Monitor emails you the same day this changes. The archive stays free.
Follow Webull →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes sharing of personal information, including payment card numbers, expiration dates, CVV codes, and billing addresses, with third-party service providers and payment processors for stated operational purposes. Service providers are contractually restricted to using the data only on Webull's behalf and pursuant to its instructions.

This analysis describes what Webull's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision explicitly authorizes disclosure of full payment card data, including CVV codes, to third-party payment processors, and authorizes sharing of personal information with analytics providers such as Google Analytics. The scope of data shared with analytics providers and the contractual controls governing those relationships are relevant to PCI DSS compliance assessments and data minimization obligations under applicable privacy law.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, payment card information including card numbers, expiration dates, CVV codes, and billing addresses is shared with third-party payment processors. Personal information is also shared with analytics service providers, subject to contractual restrictions requiring those providers to use the data only on Webull's behalf.

Cross-platform context

See how other platforms handle Third-Party Data Sharing with Service Providers and Payment Processors and similar clauses.

Compare across platforms →

Monitoring

Webull has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Webull → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We engage service providers to perform certain functions and provide certain services. For example, we use a variety of third-party services to help us understand and improve the use of our Services, such as Google Analytics. We may share your private personal information with these service providers, subject to our obligations to adhere to this Policy and any other appropriate confidentiality and security measures, and on the condition that the third parties use your private personal data only on our behalf and pursuant to our instructions. We share your payment information, including your credit or debit card number, card expiration date, CVV code, and billing address with payment services providers to process payments, prevent, detect and investigate fraud or other prohibited activities, facilitate dispute resolution such as chargebacks or refunds, and for other purposes associated with the acceptance of credit or debit cards.

Excerpt from Webull's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: Disclosure of CVV codes to third parties engages Payment Card Industry Data Security Standard (PCI DSS) requirements, which impose strict controls on the storage, processing, and transmission of cardholder data including CVV codes. The FTC Act and applicable state consumer protection statutes govern the adequacy of disclosures regarding third-party data sharing. GDPR Article 28 requires that processors be bound by written contracts specifying the scope of processing, which the policy asserts but does not detail. 2. GOVERNANCE EXPOSURE: Medium. The explicit disclosure that CVV codes are shared with payment processors is operationally relevant for PCI DSS compliance review, as PCI DSS standards prohibit storage of CVV codes post-authorization. Whether this reflects transmission-only or storage is not clarified in the document. 3. JURISDICTION FLAGS: EEA and UK residents are subject to GDPR Article 28 processor requirements, which mandate specific contractual provisions with all data processors. California residents should assess whether this sharing constitutes a sale or sharing of personal information under CPRA definitions. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify that executed data processing agreements with each named and unnamed service provider, including analytics and payment processing vendors, include the contractual restrictions described in this provision and satisfy applicable regulatory requirements in each operating jurisdiction. 5. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that payment processor agreements comply with PCI DSS, that analytics provider agreements include appropriate data processing clauses, and that the scope of data shared with each third-party category is accurately reflected in data mapping documentation.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over data security practices and disclosures involving third-party sharing of sensitive financial information.
    File a complaint →
  • CFPB
    The CFPB has authority over financial data practices, including sharing of payment and financial account information by financial services providers.
    File a complaint →

Provision details

Document information
Document
Webull Privacy Policy
Entity
Webull
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013835
Document ID
CA-D-00057
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
10f912a3d61c7caccfdda25bb9fe2f8f34e00f955fb65e4bd125a5e742c940c1
Analysis generated
July 9, 2026 04:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Webull
Document: Webull Privacy Policy
Record ID: CA-P-013835
Captured: 2026-07-09 04:04:10 UTC
SHA-256: 10f912a3d61c7cac…
URL: https://conductatlas.com/platform/webull/webull-privacy-policy/provision/CA-P-013835/third-party-data-sharing-with-service-providers-and-payment-processors/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Webull's Third-Party Data Sharing with Service Providers and Payment Processors clause do?

This provision explicitly authorizes disclosure of full payment card data, including CVV codes, to third-party payment processors, and authorizes sharing of personal information with analytics providers such as Google Analytics. The scope of data shared with analytics providers and the contractual controls governing those relationships are relevant to PCI DSS compliance assessments and data minimization obligations under applicable privacy law.

How does this clause affect you?

Under this clause, payment card information including card numbers, expiration dates, CVV codes, and billing addresses is shared with third-party payment processors. Personal information is also shared with analytics service providers, subject to contractual restrictions requiring those providers to use the data only on Webull's behalf.

Is ConductAtlas affiliated with Webull?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Webull.