-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that when a user interacts with or views a file, their IP address, specific in-file actions, and viewing timestamps may be disclosed to the file's administrator and, in some cases, to other file viewers....
Why it matters: This provision establishes that file administrators operating within enterprise or team deployments receive access to identifiable interaction data including IP addresses and specific user actions, which may create secondary data controller obligations for organizational customers subject to GDPR or CCPA....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that domain capture is enabled by default for K-12 Enterprise education accounts, resulting in automatic disclosure of names, email addresses, and profile pictures to all users sharing the same organizational email domain....
Why it matters: This provision establishes a default-on data sharing configuration for education accounts that discloses student or staff identifying information across an organization without requiring affirmative action to enable the feature, which may engage FERPA and state student privacy obligations for U.S. educational institutions....
-
Figma
· Figma Privacy Policy (Superseded URL)
Figma certifies compliance with the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, providing EU, UK, and Swiss users with an independent dispute resolution pathway through JAMS at no cost, with binding arbitration available as a final escalation mechanism under DPF rules....
Why it matters: This provision establishes a structured complaint resolution pathway for EU, UK, and Swiss users, including a 45-day initial response commitment, free referral to JAMS for unresolved complaints, and access to binding arbitration under DPF conditions, with the FTC holding enforcement jurisdiction over Figma's DPF obligations....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that third-party advertising partners are permitted to deploy tracking technologies on Figma's services to collect IP addresses, cookie identifiers, page visit data, location, and time-of-day data for use in interest-based advertising on third-party services....
Why it matters: This provision authorizes third-party advertising partners to independently collect identifiable behavioral data from Figma users across the service, and that data is then used for cross-site targeted advertising, engaging CCPA sale and sharing provisions and GDPR consent requirements for EU users....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that when a user accesses Figma through an organizational account or has their account paid for by another party, Figma will disclose that user's information to the organization or paying party upon request and grant the organization certain control rights over the user's account information....
Why it matters: This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that personal information is retained for the duration of service use or as necessary for listed business and legal purposes, and that requesting deletion of personal information requires the user to delete their Figma account entirely....
Why it matters: This provision conditions personal data deletion on full account deletion, meaning users cannot request removal of specific personal data categories while retaining their Figma account, which may interact with GDPR and CCPA data minimization and deletion rights depending on the specific data category and processing purpose involved....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that personal data transferred outside the EEA, Switzerland, and UK to non-adequate countries is safeguarded through Module 2 Standard Contractual Clauses under GDPR Article 46(2), with Swiss-law amendments and a UK Addendum for UK-originating transfers....
Why it matters: This provision documents the legal transfer mechanisms Figma relies upon for international data flows, specifying Module 2 SCCs (controller-to-processor) as the primary safeguard, which is operationally significant for enterprise customers conducting transfer impact assessments under GDPR....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that when a user acquires resources from third-party creators on Figma Community, the user's name and transaction-related personal information are disclosed to those creators, with any further information sharing governed by the individual creator's privacy policy....
Why it matters: This provision establishes that Community marketplace transactions trigger disclosure of user personal information to individual third-party creators who operate under their own independent privacy policies, creating a data governance gap that Figma does not contractually bridge for users....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that Figma recognizes GPC signals from supported browsers and treats them as CCPA opt-out requests for sale and sharing of personal information for targeted advertising, when the signal can be associated with an identifiable consumer. DNT signals are not recognized....
Why it matters: This provision operationalizes CCPA's GPC signal recognition requirement, establishing that GPC-enabled browsers trigger an opt-out of sale and sharing for targeted advertising, while also providing a manual opt-out mechanism through the Manage Cookies footer link. The policy's qualification that recognition depends on the ability to associate the signal with an identifiable consumer introduces a practical limitation on GPC effectiveness....
-
Airtable
· Airtable Privacy Policy
The policy authorizes Airtable to disclose user information to the employer, organization, or workspace owner associated with the user's account, including where the employer created the account on the user's behalf or is associated with the user's email domain....
Why it matters: This provision establishes that employees or organizational members using an Airtable account created or administered by their employer may have their account activity and personal information disclosed to that employer or workspace owner, creating an operational dependency for enterprise HR, legal, and compliance functions....
-
Airtable
· Airtable Privacy Policy
The policy discloses that Airtable collects inferences derived from usage data, including predictions about user preferences, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes....
Why it matters: This provision discloses the collection of a broad range of inferred personal data categories, including psychological and attitudinal inferences, which under CCPA are classified as a distinct category of personal information and may engage specific rights and restrictions....
-
Airtable
· Airtable Privacy Policy
The policy states that deleted Content, including personal information contained within it, may be retained in archived or backup copies to support features such as revision history and base snapshots, and that permanent deletion requires a manual request to Airtable....
Why it matters: This provision establishes that standard in-product deletion does not result in permanent removal of Content, and that permanent deletion requires a separate manual contact process, which may affect data minimization and erasure obligations under GDPR and U.S. state privacy laws....
-
Airtable
· Airtable Privacy Policy
The policy requires users to complete two separate steps to opt out of targeted advertising: first, toggling cookies off in the Cookie Preference Center or enabling Global Privacy Control, and second, submitting a separate opt-out form or email to privacy@airtable.com....
Why it matters: This provision establishes a two-step opt-out process for targeted advertising that requires both a technical cookie setting action and a separate affirmative request submission, which may require evaluation under state privacy laws that specify the permissible mechanics of opt-out mechanisms....
-
Airtable
· Airtable Privacy Policy
The policy states that Airtable reserves the right to access, retain, take possession of, delete, or deny user access to Content when it determines in its sole discretion that such action is necessary for security, rights protection, or enforcement of the Terms of Service....
Why it matters: This provision reserves broad unilateral authority for Airtable to access and take action on user Content, including denial of access, based on internal determinations made at sole discretion, which creates operational risk for enterprise customers relying on Airtable for business-critical data storage....
-
Airtable
· Airtable Privacy Policy
The policy states that linking third-party services (such as Google Drive) to Airtable authorizes Airtable to collect information from those services, and that users also become subject to the privacy policies of the third-party services they connect....
Why it matters: This provision establishes that activating third-party integrations creates a data flow from the third-party service to Airtable and subjects users to the third party's own privacy terms, creating a layered privacy governance structure that may not be fully visible to users at the point of integration....
-
Airtable
· Airtable Privacy Policy
The policy states that Airtable's services are not intended for users under 18 (or applicable local age threshold) and that Airtable will take reasonable steps to delete personal information discovered to have been collected from a child....
Why it matters: This provision establishes Airtable's age restriction at 18 rather than the 13-year threshold applicable under U.S. federal COPPA, which may create a higher age floor than legally required but also may not include the verifiable parental consent mechanisms required by COPPA if children under 13 do access the service....
-
Airtable
· Airtable Privacy Policy
The policy states that Airtable may revise the Privacy Policy at any time and will notify users via email of material revisions, with materiality determined solely by Airtable....
Why it matters: This provision reserves to Airtable the unilateral authority to determine which revisions constitute material changes requiring email notification, meaning that revisions Airtable determines to be non-material will not trigger direct user notification and will apply to previously collected information under the new terms....
-
Airtable
· Airtable Privacy Policy
The policy discloses that EEA, UK, and Swiss residents have the right to access, portability, rectification, erasure, restriction, consent withdrawal, and objection regarding their personal data, and may submit requests by email or online form....
Why it matters: This provision establishes the operational mechanism for EEA, UK, and Swiss data subject rights requests, including the specific contact method and subject line required, and confirms Airtable's recognition of its controller obligations under GDPR for these user groups....
-
Klarna
· Klarna Privacy Policy
The document states that Klarna collects app interaction data, linked bank transaction data, purchase history, preferred items, contact and identification information, financial details, device data, and interaction records for purposes including personalization, fraud prevention, and marketing....
Why it matters: This provision establishes a broad set of data categories collected by Klarna, including linked bank transaction data and behavioral and device identifiers, which collectively span financial, identity, and behavioral data types relevant to GLBA, CCPA, and GDPR compliance obligations....
-
Klarna
· Klarna Privacy Policy
The document authorizes Klarna to share personal data with cloud computing platforms, payment service providers, advertising and marketing partners, and regulatory authorities, for purposes including fraud prevention, credit risk assessment, and marketing and advertising....
Why it matters: This provision authorizes sharing of personal data, which may include financial and behavioral data, with advertising and marketing partners, a category that engages GLBA NPI sharing opt-out requirements and CCPA sale or sharing disclosure obligations given the nature of the data Klarna processes....
-
Klarna
· Klarna Privacy Policy
The document provides a GLBA-based opt-out mechanism allowing users to limit Klarna's sharing of non-public personal information with unaffiliated third parties, accessible through the Klarna app or at app.klarna.com under Settings then Privacy....
Why it matters: This provision operationalizes Klarna's GLBA opt-out obligation as a financial institution, allowing US consumers to limit sharing of NPI with unaffiliated third parties through in-app or web-based settings without requiring physical mail or phone contact....
-
Klarna
· Klarna Privacy Policy
The document states that requesting data deletion will result in termination of all agreements with Klarna and loss of access to order history and account, while Klarna retains certain data for legal compliance and fraud prevention purposes even after a deletion request....
Why it matters: This provision links the exercise of a data deletion right to termination of all Klarna agreements and account access, which is an operational consequence that consumers should be aware of before initiating a deletion request; the breadth of this linkage may warrant evaluation under GDPR's right to erasure framework, which does not generally condition erasure on agreement termination....
-
Klarna
· Klarna Privacy Policy
The document states that Klarna performs internal and third-party credit checks and receives personal data including name, date of birth, place of birth, financial information, and behavioral data from credit and fraud prevention agencies, stores, and public databases to assess product eligibility....
Why it matters: This provision establishes that Klarna receives personal data from external credit and fraud agencies, stores, and public databases in addition to data provided directly by the consumer, which is relevant to FCRA applicability in the US context and to GDPR transparency obligations regarding data obtained from third-party sources....
-
Klarna
· Klarna Privacy Policy
The document states that Klarna retains purchase history, interaction records, device details, linked bank transaction data, and preferred item data to send marketing communications, offers, product recommendations, and personalized in-app features....
Why it matters: This provision establishes that financial and behavioral data, including linked bank transactions, is used for marketing and personalization purposes, which engages GLBA restrictions on use of NPI for marketing, CCPA rights regarding use of personal information for targeted advertising, and GDPR requirements for a lawful basis for direct marketing....
-
Klarna
· Klarna Privacy Policy
The document directs California residents to a dedicated California Privacy Page for information on their privacy rights, and provides a US regional privacy notice page for general US privacy rights information, without reproducing the specific rights or mechanisms on this page....
Why it matters: This provision acknowledges CCPA applicability for California residents and directs them to a separate page, meaning the operative CCPA disclosures and opt-out mechanisms are not contained in this document and require review of the linked California Privacy Page....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel may share de-identified AI product information, including chat prompts, uploaded images, and design or text generations, from Hobby and Pro plan users with external AI business partners for model training and product development purposes, subject to opt-out through team settings....
Why it matters: This provision authorizes disclosure of de-identified AI product inputs to third-party AI business partners, creating a data flow that extends beyond Vercel's internal operations; compliance teams should evaluate whether the de-identification standard applied satisfies applicable law thresholds, particularly under GDPR and US state privacy laws where re-identification risk standards vary....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel discloses that it has shared identifiers, commercial information, and internet activity data with third-party advertising networks in the preceding 12 months in a manner that may qualify as 'selling' or 'sharing' personal information under applicable US state privacy laws....
Why it matters: This provision constitutes a disclosure of advertising-related data sharing practices that trigger opt-out rights under CCPA, CPRA, and equivalent state laws; the document states that Vercel honors GPC signals and provides a linked opt-out form, which are operationally relevant compliance mechanisms for California and other state law compliance....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel has self-certified under the EU-US DPF, UK Extension, and Swiss-US DPF programs, establishing a legal transfer mechanism for personal data from the EU, UK, and Switzerland to the US; in case of conflict, the DPF Principles take precedence over the Notice's own terms....
Why it matters: This provision establishes Vercel's stated legal basis for cross-border personal data transfers from the EU, UK, and Switzerland, with FTC enforcement jurisdiction over compliance; the DPF Principles supremacy clause creates an operative hierarchy that affects how this Notice is interpreted for EU, UK, and Swiss data subjects....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel places full legal responsibility for end user privacy compliance on its Customers, including the obligation to notify end users of data collection practices; Vercel's Notice does not cover end users whose data is processed at the Customer's direction....
Why it matters: This provision establishes that Vercel operates as a data processor for Customer-directed processing activities, with Customers bearing the controller obligations for end user personal information; organizations deploying applications on Vercel's platform must independently satisfy applicable privacy law requirements for their end users without reliance on Vercel's Notice....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel's terms authorize the transfer of personal information to third parties as part of corporate transactions including mergers, acquisitions, asset sales, and bankruptcy proceedings, with post-transfer notification to users described as possible rather than guaranteed....
Why it matters: This provision authorizes personal information to constitute a transferred asset in corporate transactions, including during pre-transaction due diligence; notification is described as occurring 'thereafter' and 'as applicable,' meaning users may not receive prior notice before their data is disclosed to prospective acquirers....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel states that it uses AI and automated decision-making to analyze personal information but asserts that it does not apply these technologies to decisions with legal or similarly significant effects on users....
Why it matters: This provision addresses GDPR Article 22 automated decision-making requirements by asserting that Vercel's automated processing does not produce legally significant decisions; this assertion limits the applicability of data subject rights to object to automated decisions, though the practical scope of 'similarly significant effects' involves interpretive uncertainty....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel uses cookies and similar tracking technologies on its sites and services, states that it obtains consent where required by applicable law, and directs users to its Cookie Notice for management options....
Why it matters: This provision conditions consent for cookie and tracking technology use on applicable law requirements, meaning the consent mechanism applied may vary by jurisdiction; users are directed to a separate Cookie Notice for specific opt-out and preference management options....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel retains personal information for the minimum necessary period to fulfill legal, contractual, and legitimate business purposes, after which it commits to deletion or anonymization; backup copies that cannot be immediately deleted will be retained securely....
Why it matters: This provision establishes Vercel's stated retention standard as the minimum necessary period, which aligns with GDPR storage limitation principles; the provision does not specify concrete retention timelines for specific data categories, leaving the practical duration of retention determined by Vercel's internal assessments of legal and business necessity....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel restricts its Sites and Services to users age 16 and older, states it does not knowingly collect personal information from individuals under 16, and commits to removing such information if discovered....
Why it matters: The stated minimum age of 16 aligns with GDPR's default age of digital consent in many EU member states and exceeds COPPA's US minimum of 13; this provision creates a compliance boundary relevant to any Customer deploying Vercel-hosted services accessible to minors....
-
Mercury
· Mercury Privacy Policy
The policy authorizes collection of voiceprints, facial scans, and biometrics extracted from photographs for identity verification and related purposes, and classifies this data as Sensitive Personal Information under California law....
Why it matters: This provision authorizes collection of biometric identifiers that are subject to distinct statutory frameworks in several U.S. states, including Illinois BIPA, Texas CUBI, and Washington state law, which impose written consent, retention schedule, and data destruction requirements beyond what this policy's general language specifies....
-
Mercury
· Mercury Privacy Policy
The policy states that Mercury does not sell Personal Information for money but acknowledges that advertising-related cookie and tracking technologies may qualify as a 'sale' or 'sharing' under applicable U.S. state privacy laws, and that this does not apply to users under 16....
Why it matters: This provision establishes that Mercury's advertising tracking practices may trigger opt-out rights under CCPA and similar U.S. state privacy laws, and requires Mercury to honor opt-out signals including the Global Privacy Control; the policy states that GPC is recognized and a 'Your Privacy Choices' opt-out link is provided....
-
Mercury
· Mercury Privacy Policy
The policy states that Mercury uses AI and machine learning for fraud detection, credit application evaluation, document verification, and transaction categorization, and that decisions with legal consequences, financial implications, or material effects on service access always include human oversight rather than being made by AI alone....
Why it matters: This provision establishes Mercury's stated operational safeguard against fully automated consequential decision-making, which is relevant to GDPR Article 22 requirements for EEA users and to emerging U.S. state automated decision-making regulations; the policy does not specify the mechanism or documentation standard for human oversight....
-
Mercury
· Mercury Privacy Policy
The policy states that SMS opt-in consent data and mobile phone numbers will not be sold, rented, or shared for marketing purposes, and will only be passed to telecommunications carriers under confidentiality agreements solely to deliver SMS messages....
Why it matters: This provision establishes an express contractual restriction on SMS opt-in data use and third-party disclosure, which is operationally distinct from the broader data sharing permissions described elsewhere in the policy and may engage TCPA and carrier-level messaging compliance requirements....
-
Mercury
· Mercury Privacy Policy
The policy states that privacy rights requests including deletion and access may be denied in part when the Personal Information is subject to federal financial laws that are exempt from U.S. state privacy law requirements, and directs personal account users to a separate Consumer Financial Privacy Notice....
Why it matters: This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses....
-
Mercury
· Mercury Privacy Policy
The policy states that Personal Information may be stored and processed in any country where Mercury or its affiliates and service providers operate, and that EEA and UK transfers are protected by Standard Contractual Clauses and additional technical safeguards....
Why it matters: This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted....
-
Mercury
· Mercury Privacy Policy
The policy authorizes disclosure of contact identifiers, internet activity data, and geolocation data to social and advertising networks and analytics providers for the purpose of placing advertisements on third-party websites and conducting performance analytics....
Why it matters: This provision authorizes sharing of contact information, internet activity, and geolocation data with social advertising networks including Facebook Ads, Bing Ads, Google Ads, and LinkedIn Ads as identified in the cookie table, which may constitute 'sharing' under CCPA and trigger opt-out rights for California residents....
-
Mercury
· Mercury Privacy Policy
The policy authorizes collection of audio and video recordings during sales, support, research, and customer feedback calls or meetings, subject to opt-out or consent withholding, and permits disclosure of these recordings to affiliates, service providers, business partners, and regulators....
Why it matters: This provision authorizes recording of calls and meetings with opt-out or consent mechanisms, and the data disclosure table indicates these recordings may be shared with affiliates, service providers, business partners, and regulators; applicable wiretapping and call recording laws vary significantly by jurisdiction and may impose additional consent requirements beyond what this policy describes....
-
Mercury
· Mercury Privacy Policy
The policy states that Mercury's services are not directed at children under 13 and that Mercury does not knowingly collect Personal Information from users under 13, with a parental contact mechanism provided....
Why it matters: This provision establishes COPPA compliance positioning; because Mercury also states it does not knowingly sell or share Personal Information of minors under 16 elsewhere in the policy, the age threshold for data sale and sharing restrictions extends to a broader group than the under-13 service exclusion....
-
Mercury
· Mercury Privacy Policy
The policy states that Personal Information is retained based on operational, legal, tax, fraud prevention, dispute resolution, and legal defense factors, without specifying fixed retention periods for any data category, and notes that financial regulatory requirements may require extended retention....
Why it matters: The policy does not specify fixed retention timelines for any category of Personal Information, including biometric data, financial records, or audio and video recordings; this approach requires users and compliance teams to rely on Mercury's internal retention schedules rather than disclosed timeframes....
-
Synthesia
· Synthesia Privacy Policy
The policy discloses that creating an avatar on Synthesia requires processing biometric data including facial geometry and voiceprints, classified as special category data under GDPR and as biometric identifiers under the Illinois Biometric Information Privacy Act. Processing occurs for avatar generation, identity verification, fraud prevention, and AI model fine-tuning....
Why it matters: This provision establishes that avatar creation constitutes biometric data processing subject to heightened legal obligations under GDPR Article 9 and the Illinois Biometric Information Privacy Act, requiring explicit consent as a derogation and compliance with jurisdiction-specific retention, disclosure, and prohibition-on-sale requirements. Enterprise customers deploying Synthesia for employee avatar creation should assess their own obligations as data controllers under these frameworks....
-
Synthesia
· Synthesia Privacy Policy
The policy establishes that enterprise customers (employers or other purchasing entities) act as data controllers for Customer Data submitted to the platform, while Synthesia acts as data controller for Other Information it independently collects. Synthesia processes Customer Data only on customer instructions....
Why it matters: This provision allocates primary compliance responsibility for Customer Data governance to enterprise customers, establishing that those customers determine the purposes and conditions of processing for user-submitted content including avatar samples, scripts, and videos. Authorized users with questions about Customer Data handling are directed to their employer or the relevant enterprise customer rather than Synthesia....
-
Synthesia
· Synthesia Privacy Policy
The policy states that Synthesia may retain Other Information including contact data, usage data, technical data, and financial data after a user deletes their account, for purposes including legitimate business interests, audits, legal compliance, dispute resolution, and agreement enforcement. No specific maximum retention period is stated for post-deletion retention....
Why it matters: This provision reserves the right to retain user data beyond account deletion without specifying a defined post-deletion retention period, which may require evaluation under GDPR's data minimization and storage limitation principles. The absence of a stated maximum retention duration creates ambiguity for data subjects seeking to exercise erasure rights....
-
Synthesia
· Synthesia Privacy Policy
The policy explicitly states that Synthesia will not sell, lease, trade, or otherwise profit from biometric data, and extends this prohibition to its vendors. This commitment applies to facial geometry, voiceprint, and related biometric identifiers collected during avatar creation....
Why it matters: This provision directly addresses a key requirement of the Illinois Biometric Information Privacy Act and reflects a disclosure that aligns with BIPA's prohibition on selling or profiting from biometric identifiers. The explicit extension of this prohibition to vendors provides an additional layer of contractual commitment beyond Synthesia's own operations....
-
Synthesia
· Synthesia Privacy Policy
The policy states that personal data may be transferred outside the UK and EEA, with transfers protected by European Commission adequacy decisions under GDPR Article 45 or standard contractual clauses under GDPR Article 46. Users may obtain copies of applicable decisions or clauses by contacting support@synthesia.io....
Why it matters: This provision establishes the legal mechanisms Synthesia relies on for cross-border personal data transfers, directly engaging GDPR Chapter V obligations. The disclosure that biometric data may be transferred to third-party vendors including Amazon Web Services EMEA SARL is particularly relevant for compliance assessments given the special category status of biometric data under GDPR Article 9....
-
Synthesia
· Synthesia Privacy Policy
The policy enumerates GDPR-aligned data subject rights including access, portability, restriction, withdrawal of consent, rectification, erasure, objection, and the right not to be subject to solely automated decision-making. Users may exercise these rights by emailing support@synthesia.io, and may lodge complaints with the UK ICO or local EU supervisory authority....
Why it matters: This provision establishes the procedural mechanism for users to exercise GDPR and UK GDPR data subject rights directly with Synthesia, and identifies the UK ICO as the primary supervisory authority for complaint escalation. The policy notes that erasure or processing restriction may result in loss of access to some services....