Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes sharing of personal information, including payment card numbers, expiration dates, CVV codes, and billing addresses, with third-party service providers and payment processors for stated operational purposes. Service providers are contractually restricted to using the data only on Webull's behalf and pursuant to its instructions.
This analysis describes what Webull's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision explicitly authorizes disclosure of full payment card data, including CVV codes, to third-party payment processors, and authorizes sharing of personal information with analytics providers such as Google Analytics. The scope of data shared with analytics providers and the contractual controls governing those relationships are relevant to PCI DSS compliance assessments and data minimization obligations under applicable privacy law.
Under this clause, payment card information including card numbers, expiration dates, CVV codes, and billing addresses is shared with third-party payment processors. Personal information is also shared with analytics service providers, subject to contractual restrictions requiring those providers to use the data only on Webull's behalf.
Cross-platform context
See how other platforms handle Third-Party Data Sharing with Service Providers and Payment Processors and similar clauses.
Compare across platforms →Monitoring
Webull has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We engage service providers to perform certain functions and provide certain services. For example, we use a variety of third-party services to help us understand and improve the use of our Services, such as Google Analytics. We may share your private personal information with these service providers, subject to our obligations to adhere to this Policy and any other appropriate confidentiality and security measures, and on the condition that the third parties use your private personal data only on our behalf and pursuant to our instructions. We share your payment information, including your credit or debit card number, card expiration date, CVV code, and billing address with payment services providers to process payments, prevent, detect and investigate fraud or other prohibited activities, facilitate dispute resolution such as chargebacks or refunds, and for other purposes associated with the acceptance of credit or debit cards.Excerpt from Webull's Privacy Policy
1. REGULATORY LANDSCAPE: Disclosure of CVV codes to third parties engages Payment Card Industry Data Security Standard (PCI DSS) requirements, which impose strict controls on the storage, processing, and transmission of cardholder data including CVV codes. The FTC Act and applicable state consumer protection statutes govern the adequacy of disclosures regarding third-party data sharing. GDPR Article 28 requires that processors be bound by written contracts specifying the scope of processing, which the policy asserts but does not detail. 2. GOVERNANCE EXPOSURE: Medium. The explicit disclosure that CVV codes are shared with payment processors is operationally relevant for PCI DSS compliance review, as PCI DSS standards prohibit storage of CVV codes post-authorization. Whether this reflects transmission-only or storage is not clarified in the document. 3. JURISDICTION FLAGS: EEA and UK residents are subject to GDPR Article 28 processor requirements, which mandate specific contractual provisions with all data processors. California residents should assess whether this sharing constitutes a sale or sharing of personal information under CPRA definitions. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify that executed data processing agreements with each named and unnamed service provider, including analytics and payment processing vendors, include the contractual restrictions described in this provision and satisfy applicable regulatory requirements in each operating jurisdiction. 5. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that payment processor agreements comply with PCI DSS, that analytics provider agreements include appropriate data processing clauses, and that the scope of data shared with each third-party category is accurately reflected in data mapping documentation.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision explicitly authorizes disclosure of full payment card data, including CVV codes, to third-party payment processors, and authorizes sharing of personal information with analytics providers such as Google Analytics. The scope of data shared with analytics providers and the contractual controls governing those relationships are relevant to PCI DSS compliance assessments and data minimization obligations under applicable privacy law.
Under this clause, payment card information including card numbers, expiration dates, CVV codes, and billing addresses is shared with third-party payment processors. Personal information is also shared with analytics service providers, subject to contractual restrictions requiring those providers to use the data only on Webull's behalf.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Webull.