-
Coinbase
· Coinbase Fee Schedule
Coinbase includes a spread in the price quoted to users for simple buy, sell, and convert orders, and the document states Coinbase may retain any excess spread generated from those transactions....
Why it matters: This provision establishes that the effective price paid or received by consumers for trades includes an undisclosed margin above or below the market rate, and that Coinbase retains any excess above the amount required to execute the transaction. The spread is visible on the order preview screen but is not expressed as a fixed percentage, meaning the cost to the consumer may vary across similar transactions....
-
Coinbase
· Coinbase Fee Schedule
This provision discloses that when Coinbase batches multiple users' transactions together for network submission, the total estimated network fees charged to those users may collectively exceed the actual network fee that Coinbase pays, with Coinbase retaining the difference....
Why it matters: This provision establishes that the network fee charged to an individual user is based on an estimate of standalone transaction costs, and that efficiency gains realized by batching are not passed through to users. The resulting difference between aggregate user charges and Coinbase's actual cost is retained by Coinbase....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a commission of 35% of staking rewards earned by standard account holders across supported assets including ETH, SOL, and ADA, with reduced commission rates of 25.25% to 31.75% available to tiered Coinbase One members....
Why it matters: This provision establishes that Coinbase retains 35% of all staking rewards generated for standard users on supported assets, which directly reduces the effective staking yield received by consumers. The tiered Coinbase One commission structure creates a materially different cost basis for subscription members versus non-members....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges an additional service fee on DEX trades beyond the standard trading fee, may retain any excess service fee, and explicitly excludes this fee from the Coinbase One subscription's zero-fee trading benefit....
Why it matters: This provision establishes a fee category for DEX trades that operates independently of the Coinbase One subscription benefit structure, meaning subscribers who pay for zero-fee trading are nonetheless subject to a separate service fee on all DEX transactions. The document also states that DEX aggregators routing trades may retain any price improvement over the quoted price as a fee....
-
Coinbase
· Coinbase Fee Schedule
If Coinbase liquidates a user's Bitcoin collateral under a loan agreement, it charges a flat fee of 2% of the total transaction value at the time of liquidation....
Why it matters: This provision establishes a liquidation fee triggered by collateral sale events under Coinbase lending arrangements, creating a fixed cost that applies at the point when a borrower's collateral position is being reduced, potentially compounding financial exposure during adverse market conditions....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a network fee for all recovery attempts of unsupported cryptocurrency sent to a Coinbase account, plus an additional 5% fee on the portion of the estimated recovery value exceeding $100, with a disclaimer that estimated value may differ from actual market value....
Why it matters: This provision establishes a fee structure for asset recovery services where the 5% fee is calculated on an estimated value that the document itself acknowledges may differ from actual market value, creating a situation where the fee basis may not align with the consumer's ultimate realized value....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a 0.2% processing fee on Lightning Network bitcoin transfers and a 0.01% processing fee capped at 20 USDT on USDT withdrawals, with separate network transaction fees applying in addition to both processing fees....
Why it matters: This provision establishes explicit percentage-based processing fees for Lightning Network and USDT transfers that are charged in addition to separate network transaction fees, creating a dual-fee structure for these transfer types. The 20 USDT cap on USDT processing fees provides a defined maximum cost for large USDT withdrawals....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a 0.10% processing fee on the net USDC conversion volume exceeding $5 million within any rolling 30-day period, with net volume calculated by netting USDC-to-USD and USD-to-USDC conversions within that period....
Why it matters: This provision establishes a fee structure specifically applicable to high-volume USDC conversion users, using a net rather than gross volume calculation methodology for the threshold, which means bidirectional conversion activity within the 30-day window reduces the effective fee basis....
-
Coinbase
· Coinbase Fee Schedule
The document states that all fees and charges disclosed in the schedule are subject to change without specifying a notice period, notice method, or effective date requirement for fee changes....
Why it matters: This provision reserves Coinbase's right to modify any fee or charge in this schedule without specifying a notice period, notice mechanism, or advance-notice obligation to users, which may interact with applicable consumer financial protection and money transmission regulations that impose notice requirements for material changes to fee terms....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to make automated decisions that materially and detrimentally affect individual rights in high-risk domains including employment, healthcare, finance, legal matters, housing, insurance, or social welfare, unless human supervision is present....
Why it matters: This provision places a human supervision requirement on institutional deployments of Google generative AI in regulated high-risk domains, creating a user-side compliance obligation that intersects with EU AI Act high-risk system requirements and GDPR Article 22 automated decision-making provisions....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits users from representing AI-generated content as having been created solely by a human when the intent is to deceive....
Why it matters: This provision establishes a disclosure obligation tied to AI content provenance, which intersects with emerging EU AI Act transparency requirements for AI-generated content and state-level synthetic media disclosure statutes in the United States....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to process personal data or biometric information without obtaining legally required consent, framing this as a violation of others' rights....
Why it matters: This provision places user-side responsibility for ensuring legally required consent when using personal or biometric data as inputs to generative AI, engaging GDPR, CCPA, and state biometric privacy statutes such as Illinois BIPA....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy categorically prohibits generating or distributing content related to child sexual abuse or exploitation through Google's generative AI products....
Why it matters: This provision reflects legal obligations under statutes including the PROTECT Act and COPPA, and aligns with platform liability frameworks under federal law; it is a non-negotiable absolute prohibition with no stated exceptions....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to generate or distribute content that facilitates spam, phishing, malware, infrastructure disruption, or circumvention of Google's abuse protections and safety filters, including prompt manipulation designed to bypass policy restrictions....
Why it matters: This provision directly addresses adversarial use of generative AI for security attacks and model manipulation, including jailbreaking attempts, and places user-side responsibility for not circumventing Google's safety infrastructure....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to facilitate fraud, impersonation of individuals without explicit disclosure, misleading claims of expertise in sensitive areas, and false information about governmental or democratic processes or harmful health practices, where the intent is deception....
Why it matters: This provision covers a range of AI-facilitated deception categories with relevance to election integrity, public health information, and financial fraud, placing the conduct prohibition on the user and conditioning it on deceptive intent....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy reserves Google's discretion to grant exceptions to any of the stated prohibitions based on educational, documentary, scientific, or artistic grounds, or where public benefits are assessed to outweigh harms....
Why it matters: This provision grants Google unilateral discretion to determine when exceptions apply, without specifying a procedural mechanism, eligibility criteria, or appeal process for users seeking exception status....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using Google's generative AI to build, generate, or distribute tools or content that enable tracking or monitoring individuals without their consent....
Why it matters: This provision engages privacy law requirements across multiple jurisdictions, including GDPR provisions on lawful data processing, CCPA, and state-level electronic surveillance statutes, placing user-side responsibility for ensuring consent before using generative AI for tracking or monitoring applications....
-
Airbnb
· Airbnb Privacy Policy
Airbnb's privacy governance is distributed across a main Privacy Policy and multiple supplemental documents; users are instructed to identify and review the supplements applicable to their geography and services....
Why it matters: This provision establishes that operative data rights and obligations are not contained in a single document but are distributed across geographic and service-specific supplements, requiring users and compliance teams to identify and review multiple documents to understand the full scope of applicable terms....
-
Airbnb
· Airbnb Privacy Policy
Airbnb maintains a separate privacy notice specifically addressing DAC7-related data processing, which governs personal information collected about individuals (including hosts) for EU platform economy tax reporting purposes, potentially including individuals who are not direct Airbnb account holders....
Why it matters: The DAC7 Privacy Notice indicates that Airbnb processes personal data for EU tax authority reporting obligations that may apply to individuals regardless of whether they have a direct contractual relationship with Airbnb, creating a distinct processing purpose and notice obligation separate from the main user privacy policy....
-
Airbnb
· Airbnb Privacy Policy
Airbnb maintains separate privacy supplements for at least seven geographic jurisdictions, indicating that applicable data rights, processing terms, and disclosures vary by the user's country of residence or location....
Why it matters: The existence of jurisdiction-specific supplements indicates that data subject rights (such as access, deletion, portability, and opt-out), lawful processing bases, and data sharing disclosures are defined at the supplement level and are not uniform across Airbnb's user base....
-
Airbnb
· Airbnb Privacy Policy
Airbnb maintains four service-specific privacy supplements covering Airbnb Creators, the Airbnb-friendly Marketplace, Enterprise Customers and Airbnb for Work, and Insurance, indicating that data handling terms differ across these product contexts....
Why it matters: This provision establishes that users of specific Airbnb services are governed by supplement-level privacy terms in addition to the main policy; the applicable processing activities, data categories, and sharing terms for these services are defined in documents not reproduced in this index....
-
Airbnb
· Airbnb Privacy Policy
The document states that Airbnb.org is a separate and independent legal entity from Airbnb, Inc., and maintains its own privacy policy governing data collected through that platform....
Why it matters: This provision clarifies that users who interact with Airbnb.org are subject to a distinct privacy framework under a separate legal entity; data handling practices, rights, and obligations applicable to Airbnb.org are not governed by the Airbnb, Inc. privacy policy or its supplements....
-
Airbnb
· Airbnb Privacy Policy
The privacy framework index includes a reference to a separate Cookie Policy, indicating that tracking technology practices are governed by a distinct document rather than the main Privacy Policy....
Why it matters: The Cookie Policy reference establishes that tracking technology disclosures, consent mechanisms for non-essential cookies, and opt-out procedures for behavioral tracking are addressed in a separate document; users and compliance teams must review that document to assess applicable tracking practices....
-
Visa
· Visa Privacy Notice
The Global Privacy Notice governs Visa's collection, use, and disclosure of Personal Information globally, supplemented by jurisdiction-specific notices and a separate Cookie Notice covering cookies, tags, and similar online data collection....
Why it matters: The operative data processing terms, lawful bases, sharing categories, and retention schedules are distributed across the Global Privacy Notice and at least fifteen regional supplements, meaning no single document contains the complete picture of Visa's data practices applicable to a given user....
-
Visa
· Visa Privacy Notice
Visa publishes jurisdiction-specific supplemental privacy notices for at least twelve regions, stating that these notices provide information required by applicable local law in addition to the Global Privacy Notice....
Why it matters: This provision establishes that users in covered jurisdictions are subject to region-specific privacy terms that may grant rights or impose obligations beyond the Global Privacy Notice, requiring users and compliance teams to consult the applicable regional notice to understand the full scope of their rights....
-
Visa
· Visa Privacy Notice
Certain Visa products and platforms publish their own privacy notices at sign-up that reflect business-specific requirements applicable to those services, in addition to the Global Privacy Notice....
Why it matters: This provision establishes that the Global Privacy Notice does not necessarily govern all data practices for all Visa products; users of specific platforms are directed to read product-level notices at sign-up to understand the applicable data terms for that service....
-
Visa
· Visa Privacy Notice
Visa maintains a separate Open Banking Privacy Notice applicable in jurisdictions where open banking services are available; users in other regions are redirected to the Global Privacy Notice....
Why it matters: The Open Banking Privacy Notice governs a distinct set of data practices associated with open banking services, which involve access to financial account data and third-party data sharing under regulatory frameworks that differ from standard payment card data processing....
-
Visa
· Visa Privacy Notice
Visa publishes a separate U.S. Social Security Number Policy and Sensitive Personal Information Statement governing its handling of Social Security numbers and other sensitive personal information categories for U.S. users....
Why it matters: The existence of a dedicated policy for Social Security numbers and sensitive personal information indicates that Visa collects and processes these data categories for at least some U.S. users, which triggers heightened obligations under multiple U.S. state privacy laws and the FTC's Safeguards Rule....
-
Visa
· Visa Privacy Notice
Visa publishes a separate Cookie Notice disclosing its practices regarding cookies, tags, and similar online data collection technologies....
Why it matters: The Cookie Notice governs Visa's use of cookies, tags, and similar tracking technologies, which may collect identifiers, browsing activity, and device information; the applicable consent and opt-out mechanisms for these technologies are addressed in that separate notice rather than in the Global Privacy Notice....
-
Visa
· Visa Privacy Notice
Visa provides three channels for privacy rights requests: an online Privacy Rights Portal, email to [email protected], and postal mail to the Visa Global Privacy Office at 900 Metro Center Blvd., Foster City, CA 94404; users are instructed not to include sensitive information such as account numbers in email submissions....
Why it matters: This provision establishes the operative mechanisms through which users may submit requests to exercise privacy rights under applicable laws, including the specific contact addresses and a caution regarding sensitive information in email communications....
-
Arlo
· Arlo Privacy Policy
The Arlo website footer references a 'Your Privacy Choices' link, indicating the existence of a privacy preference or opt-out mechanism, but the substantive terms of that mechanism are not present in the submitted text....
Why it matters: The presence of a 'Your Privacy Choices' link is consistent with disclosure requirements under the California Consumer Privacy Act and similar state privacy laws, but the scope, categories of data covered, and method of exercising choices cannot be assessed from the navigation text alone....
-
Arlo
· Arlo Privacy Policy
The Arlo website footer includes a 'Manage Cookies' option, indicating the existence of a cookie consent or preference management interface, but the substantive scope of that control is not present in the submitted text....
Why it matters: A cookie management interface is associated with consent requirements under the EU General Data Protection Regulation and ePrivacy Directive for users in the EU and EEA, and with similar requirements in other jurisdictions. The categories of cookies covered, the granularity of consent options, and the technical implementation cannot be assessed from the footer reference alone....
-
Arlo
· Arlo Privacy Policy
The Arlo website footer lists RapidSOS as a named partner, indicating a third-party partnership relationship, but no details of data sharing, service scope, or contractual terms involving RapidSOS are present in the submitted text....
Why it matters: RapidSOS is a platform that routes data to emergency services; its inclusion as an Arlo partner may implicate data sharing provisions involving sensitive location and device data with emergency response infrastructure, which would ordinarily require clear disclosure in the privacy notice....
-
StockX
· StockX Privacy Policy
The policy states that StockX has sold or shared personal identifiers, transaction and commercial data, and internet or electronic usage data with advertising and analytics partners and data brokers in the preceding 12 months....
Why it matters: This provision discloses that personal data including identifiers and transaction histories has been transferred to data brokers, a category of recipient that may independently aggregate, re-sell, or further process that data outside StockX's direct control. Under CCPA, this disclosure triggers specific consumer opt-out rights and data broker registration obligations that compliance teams should evaluate....
-
StockX
· StockX Privacy Policy
The policy states that StockX collects facial geometry biometric data through a third-party provider named Persona for identity verification and fraud prevention, with user consent sought prior to collection, and that Persona may use collected biometric data to improve its own verification services....
Why it matters: This provision establishes that biometric facial geometry data is collected by a named third party (Persona) and that Persona retains authority to use that data for its own service improvement purposes, meaning biometric data collected in connection with StockX identity verification may be processed by Persona independently of the original verification purpose. Compliance teams should evaluate whether this arrangement satisfies written consent, retention, and third-party use limitation requirements under applicable biometric privacy statutes....
-
StockX
· StockX Privacy Policy
The policy states that StockX uses third-party session replay technology to record and reproduce user interactions on the site and apps, including mouse movements, clicks, page visits, scrolling, and tapping, for quality control, customer service, fraud prevention, and marketing purposes....
Why it matters: This provision establishes that a comprehensive record of user on-site behavior, including keystroke-level interactions, is captured by a third-party service provider and transferred to and stored by that provider. The use of session replay for marketing purposes, in addition to operational purposes, and the transfer of interaction recordings to a third party may require evaluation under applicable state electronic communications and wiretapping statutes....
-
StockX
· StockX Privacy Policy
The CCPA disclosure table states that StockX has collected and shared sensitive personal information including Social Security numbers, VAT identification numbers, tax identification numbers, and government-issued identification numbers with service providers, identity verification providers, business partners, professional advisors, affiliates, and government entities....
Why it matters: This provision discloses that sensitive personal information, including Social Security numbers, is shared with business partners and professional advisors in addition to identity verification and law enforcement contexts. CCPA imposes specific limitations on the use and disclosure of sensitive personal information, and compliance teams should evaluate whether the disclosed sharing practices satisfy CCPA's restrictions on sensitive data processing....
-
StockX
· StockX Privacy Policy
The policy states that opting out of data sales and targeted advertising requires completing separate actions in two distinct platform locations: the cookie management portal accessed via the 'Your Privacy Choices' link and the account-level Data Sharing Preferences settings....
Why it matters: This provision establishes that a single opt-out action does not fully effectuate a CCPA 'Do Not Sell or Share My Personal Information' request; users must complete separate actions in both the cookie management portal and account settings. Compliance teams should evaluate whether this two-step mechanism satisfies CCPA opt-out usability and GPC recognition requirements....
-
StockX
· StockX Privacy Policy
The policy states that personal data collected from all users will be processed in the United States, and that for EEA and UK users, transfers rely on European Commission Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms under applicable law....
Why it matters: This provision establishes that all user data is processed in the United States and discloses that EEA and UK transfers rely on Standard Contractual Clauses or equivalent mechanisms. Compliance teams should verify that the SCCs in use reflect current post-Schrems II requirements and that supplementary measures are implemented where the legal framework of the recipient country requires evaluation....
-
StockX
· StockX Privacy Policy
The policy states that when a purchase is made from a seller in the Verified Seller Program, Live Shopping Platform, or Listings Marketplace, personal identifiers, transaction data, and internet or electronic usage data are shared with those individual sellers....
Why it matters: This provision establishes that individual marketplace sellers receive buyer personal identifiers, transaction data, and internet or electronic usage data upon a purchase. Internet or electronic usage data is a category that extends beyond typical shipping and fulfillment data, and the scope of data shared with individual sellers may warrant review relative to user expectations and applicable data minimization requirements....
-
StockX
· StockX Privacy Policy
The policy states that StockX does not knowingly collect personal information from users under age 16 and commits to deleting any such data if inadvertently collected....
Why it matters: This provision establishes a minimum age threshold of 16, which exceeds the COPPA threshold of 13, and commits to deletion of data collected from users under 16. The reliance on a 'knowingly' standard means the protection depends on self-reporting and detection rather than active age verification mechanisms....
-
StockX
· StockX Privacy Policy
The policy states that personal data is retained for as long as needed to provide services or fulfill collection purposes, with extensions permitted for legal obligations and dispute resolution, and that aggregate data may be retained indefinitely for research and service development....
Why it matters: This provision does not specify fixed retention periods for any data category, relying instead on purpose-based criteria and a list of factors. The authorization to retain aggregate information beyond stated retention periods for research and development purposes, without a defined timeline, creates an open-ended data retention authorization....
-
StockX
· StockX Privacy Policy
The policy states that users have jurisdiction-dependent rights including access, portability, correction, deletion, processing restriction, objection, post-death instructions, and targeted advertising opt-out, and that StockX makes efforts to honor access, portability, deletion, and correction requests from all users regardless of jurisdiction....
Why it matters: This provision establishes a unified Personal Data Access Request portal for exercising data rights and commits to honoring access, portability, deletion, and correction requests globally, which extends certain rights beyond jurisdictions where they are legally mandated. The inclusion of post-death data instructions is a disclosure not universally present in comparable platform privacy policies....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble may sell or share Personal Information as defined under the CCPA in connection with targeted or behavioral advertising, and that users may opt out by emailing Rumble with a specified subject line....
Why it matters: This provision establishes that Rumble's advertising practices may constitute a sale or sharing of Personal Information under the CCPA, triggering opt-out rights for California residents and parallel opt-out obligations under multiple state privacy statutes. The opt-out mechanism is limited to an email request rather than an in-platform toggle, which compliance teams should evaluate against applicable state requirements....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble and its third-party advertising partners may collect and process political opinion data as sensitive personal information for the purpose of providing personalized advertising....
Why it matters: Under GDPR, political opinion data is classified as a special category of personal data subject to heightened processing restrictions and generally requires explicit consent. This provision's authorization of political opinion data processing for advertising purposes may require evaluation against GDPR Article 9 requirements and applicable national implementations across EU member states....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble does not respond to Do Not Track browser signals, and that activating DNT will not affect data collection. The policy separately states that Rumble does recognize and respond to browser-based universal opt-out mechanisms or device-level plug-ins....
Why it matters: This provision establishes that standard browser DNT signals do not alter Rumble's data collection practices, while the policy separately acknowledges recognition of universal opt-out mechanisms. Compliance teams should evaluate whether state laws requiring recognition of universal opt-out signals, such as Colorado's, are satisfied by the stated universal opt-out mechanism recognition....
-
Rumble
· Rumble Privacy Policy
The policy states that agreeing to the Privacy Policy constitutes consent to sharing video-viewing activity, video titles, thumbnails, device identifiers, and IP addresses with social networking sites for personalized content and advertising purposes on Rumble and other platforms....
Why it matters: This provision treats agreement to the general Privacy Policy as consent to sharing video-viewing history and identifying data with social networking sites, which may require evaluation under GDPR's consent requirements, including the standards of specificity and granularity, and under the Video Privacy Protection Act (VPPA) in the U.S., which restricts disclosure of video viewing records....
-
Rumble
· Rumble Privacy Policy
The policy states that Personal Information may be transferred in connection with a merger, acquisition, bankruptcy, or similar transaction, and that users may opt out of such transfer if the successor entity has not committed to maintaining equivalent privacy protections....
Why it matters: This provision establishes a conditional opt-out right for users whose Personal Information is transferred in a business transaction, conditioned on whether the successor entity has committed to equivalent privacy protections. The policy does not specify the mechanism or timeline for exercising this opt-out right....
-
Rumble
· Rumble Privacy Policy
The policy states that EEA/EU, UK, and other users in jurisdictions requiring affirmative consent are not served non-essential cookies until they accept via a cookie banner, and that accepting cookies constitutes consent to collection, processing, and disclosure of all Personal Information gathered through those cookies....
Why it matters: This provision establishes a tiered cookie consent mechanism for EEA/EU and UK users, distinguishing between strictly necessary cookies and non-essential cookies requiring affirmative consent. The policy states that cookie consent is also treated as consent to the processing and disclosure of all Personal Information collected through cookies, which compliance teams may wish to evaluate against GDPR's consent specificity requirements....
-
Rumble
· Rumble Privacy Policy
The policy enumerates California residents' rights under the CCPA to know, delete, correct, and obtain a portable copy of their Personal Information, with specified response timelines of 10 business days for confirmation and 45 days for full response, extendable to 90 days....
Why it matters: This provision establishes the procedural framework for California residents to exercise CCPA rights, including identity verification requirements, authorized agent procedures, and specific response timelines. The policy states that rights requests may be exercised twice per year free of charge and that the right to non-discrimination applies to users who exercise these rights....