-
Marqeta
· Marqeta Privacy Policy
The document states that personal information including identifiers, internet and network data, and inferences derived from website interactions may be disclosed to social media, advertising, and analytics providers in a manner the policy characterizes as potentially qualifying as a CCPA sale or sharing for cross-context behavioral advertising. California residents can opt out of these disclosures....
Why it matters: This provision requires Marqeta to maintain a compliant CCPA opt-out mechanism for California residents and to honor Global Privacy Control signals as an opt-out preference signal, with the California Privacy Protection Agency as a relevant enforcement authority. The provision applies specifically to website-derived data and not to Marqeta's payment processing or card program management services, which are governed separately....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta will honor Global Privacy Control opt-out signals but specifies three scenarios in which the association between a device and a prior opt-out signal may be lost: use of a different browser, browser reinstallation or certain upgrades, and clearing of cookies or browsing data. In those scenarios, the opt-out preference may not be applied....
Why it matters: This provision describes the technical scope and limitations of Marqeta's GPC signal recognition mechanism, which is the primary opt-out pathway for CCPA sale and sharing disclosed in Section 3 of the California supplemental notice. The stated limitations on signal persistence may warrant evaluation against California Privacy Protection Agency guidance on the durability and accessibility of opt-out mechanisms....
-
Marqeta
· Marqeta Privacy Policy
The document explicitly states that personal data processed in connection with Marqeta's issuer payment processing and card program management services is outside the scope of this Website Privacy Notice and is governed by a separate Services Privacy Notice....
Why it matters: This provision establishes that individuals whose personal data is processed through Marqeta's payment and card program infrastructure are subject to different and separately published privacy terms, which creates a material distinction between the rights and protections described in this notice and those applicable to payment services data subjects....
-
Marqeta
· Marqeta Privacy Policy
The document designates Marqeta Inc. (U.S.), Marqeta UK Ltd., and Marqeta sp. z.o.o. (Poland) as joint data controllers for EEA and UK processing under this notice, with Marqeta U.S. identified as the primary controller responsible for compliance and rights request management....
Why it matters: This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta participates in the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks as certified by the U.S. Department of Commerce, and that the Data Privacy Framework Notice takes precedence over this Website Privacy Notice in the event of a conflict regarding transatlantic transfers....
Why it matters: Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement authority for DPF compliance under U.S. law. The document's statement that the DPF Notice governs in the event of a conflict means that the full scope of data subject rights for international transfers requires review of both this notice and the separately published DPF Notice....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Marqeta
· Marqeta Privacy Policy
The document states that personal data is retained for variable periods determined by service necessity, legal and regulatory obligations, dispute resolution, and contractual requirements, with retention schedules specified in an internal records retention policy. At the end of the applicable retention period, data will be deleted or de-identified....
Why it matters: The policy does not publish specific retention periods for individual data categories in this notice, instead referencing an internal records retention policy and schedule that is not reproduced here. This means data subjects cannot determine the applicable retention period for their data from this document alone....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta and its third-party service providers may log session-level behavioral data including clicks, page visits, text entered, and time spent on pages, and that this data may be disclosed to third parties for Marqeta's business purposes including marketing and security....
Why it matters: The explicit reference to logging text entered during sessions is operationally distinct relative to commonly observed tracking disclosures and may encompass form field content entered before submission. The document authorizes disclosure of session-level data to third parties for business purposes, which in combination with the CCPA sale and sharing provision means this data category may be subject to opt-out rights....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta's website services are not directed at individuals under 16, that Marqeta does not intentionally collect personal data from this age group, and that any such data discovered will be promptly deleted. The age threshold of 16 is higher than the COPPA threshold of 13....
Why it matters: The document sets the age threshold for children's data protection at 16, which aligns with GDPR Article 8's default age of digital consent in the absence of member state modification, and exceeds the COPPA threshold of 13 applicable in the United States. The CCPA supplemental notice separately confirms that Marqeta does not disclose personal information of individuals under 16 for monetary or other valuable consideration....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta supplements internally collected data with personal data obtained from data providers and aggregators, social media sources, co-branded marketing partners, third-party service providers acting on Marqeta's behalf, and public sources including social networking websites....
Why it matters: The use of data providers and aggregators to supplement first-party data collection is a practice that may require evaluation under applicable law, particularly regarding notice and consent obligations in jurisdictions where data subjects have not directly provided their information to Marqeta. GDPR's transparency requirements under Article 14 apply where personal data is not obtained directly from the data subject....
-
Marqeta
· Marqeta Privacy Policy
The document states that material changes to the notice will be communicated via prior notice and, where required by applicable law, consent will be obtained before those changes take effect; non-material changes will be implemented by posting an updated version on the website without prior notification....
Why it matters: The distinction between material and non-material changes determines whether users receive advance notice or consent requests before new data practices take effect. The document does not define the criteria for determining whether a change is material, which means the classification of any given change is determined by Marqeta....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs may collect personally identifiable information including name, phone number, and postal address, used for purposes of contact and identification....
Why it matters: The provision uses an open-ended 'including but not limited to' formulation that does not limit collection to the listed categories, which means actual data collection could extend beyond name, phone number, and postal address without additional disclosure. Compliance teams should evaluate whether the categories disclosed align with actual data processing activities....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs automatically collects log data on each visit, including IP address, browser version, pages visited, visit timestamps, time spent on pages, and unspecified 'other statistics.'...
Why it matters: IP addresses are classified as personal data under GDPR in the EU, and the inclusion of 'other statistics' creates an open-ended category of automatically collected data that is not bounded by the provision's enumerated examples. The policy does not state a retention period for log data....
-
Modal
· Modal Privacy Policy
The policy states that unspecified third-party companies and individuals engaged by Modal Labs for service facilitation, delivery, and analytics are granted access to users' personal information, subject to an obligation not to use or disclose it beyond their assigned tasks....
Why it matters: The provision does not identify the third parties receiving personal data, does not describe the contractual mechanism through which the stated obligation is enforced, and does not specify which categories of personal data are shared with which categories of third parties. This structure may be insufficient to satisfy GDPR processor agreement requirements or CCPA disclosure obligations for categories of third parties to whom personal information is disclosed....
-
Modal
· Modal Privacy Policy
The policy states that modal.com uses cookies to collect information and improve the service, that users may accept or refuse cookies through browser settings, and that refusing cookies may result in limited access to some portions of the service....
Why it matters: The provision does not identify the specific cookies used, distinguish between functional and tracking cookies, or describe what information is collected through cookies, which may be insufficient under EU ePrivacy Directive and GDPR cookie consent requirements applicable to EU users....
-
Modal
· Modal Privacy Policy
The policy states that the service is not directed at users under 13, that Modal Labs does not knowingly collect personal information from children under 13, and that upon discovery such information will be immediately deleted; parents or guardians may contact the company to request action....
Why it matters: This provision reflects a standard COPPA-aligned disclosure for services not directed at children. The policy does not provide a specific contact address for parental requests, which may create a practical barrier to exercising the stated deletion right....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs may update the privacy policy at any time, that changes take effect immediately upon posting, and that notification is provided solely by posting the updated policy on the same page....
Why it matters: The provision establishes that policy changes become effective immediately upon posting without advance notice, email notification, or a defined review period, which may be inconsistent with GDPR requirements for meaningful notification of material changes to data processing terms and may limit users' practical ability to respond to changes before they take effect....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs uses commercially acceptable means to protect personal information but does not guarantee absolute security against data breaches or unauthorized access....
Why it matters: The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insufficient to satisfy GDPR's requirement for appropriate technical and organizational security measures....
-
Modal
· Modal Terms of Service
The agreement states that minimum fee commitments in Service Orders are based on the service tier purchased rather than actual usage, are non-cancelable during the term, and are not refundable except in the limited termination scenarios described in section 3.2....
Why it matters: This provision establishes that Customers are financially obligated for the full committed service term and amount regardless of whether they use the Service, creating a fixed cost exposure that does not vary with actual consumption. The only exception pathways are those described in the termination section, which require material breach or specified insolvency events....
-
Modal
· Modal Terms of Service
The agreement states that Modal will not use Customer Data to train AI models or ingest Customer Data into large language models without the Customer's prior written consent, and that Input and Output from AI Tools are classified as Customer Data....
Why it matters: This provision establishes a contractual prohibition on AI model training using Customer Data as a default, requiring affirmative written consent before any such use. Because Input and Output are classified as Customer Data, this prohibition extends to materials submitted to and generated by Modal's AI Tools....
-
Modal
· Modal Terms of Service
The agreement states that Customer grants Modal a perpetual, irrevocable, worldwide, sublicensable, royalty-free license to use Feedback for any purpose, with an exclusion for Customer Data and Customer Confidential Information contained in the Feedback....
Why it matters: This provision establishes that any suggestions, comments, or other feedback submitted by Customer to Modal are subject to a broad, perpetual, and irrevocable license that cannot be withdrawn, and that Modal may sublicense and transfer this rights grant to third parties. The exclusion for Customer Data and Confidential Information contained in Feedback provides a carveout, but the boundary between Feedback and embedded Customer Data may require assessment in practice....
-
Modal
· Modal Terms of Service
The agreement states that Modal may collect and use aggregate or permanently anonymized usage data for its own business purposes both during and after the agreement term, and that this right survives termination. The definition of Service Metrics requires that the data not identify an individual or Customer and that technical safeguards against reidentification be in place....
Why it matters: This provision establishes a post-termination data retention and use right for Modal covering aggregate and anonymized usage data, which operates as an exception to the general data deletion obligations upon termination. The enforceability of the anonymization standard as a basis for excluding this data from privacy law obligations depends on the robustness of the anonymization and reidentification safeguards, which the agreement states are implemented but does not detail in the main terms....
-
Modal
· Modal Terms of Service
The DPA states that Modal will provide 30 days advance notice of subprocessor changes via website update and email notification (if Customer has self-enrolled), but that the only available remedy for a Customer objection to a new subprocessor is termination of the subscription....
Why it matters: This provision establishes that Customer cannot block a new subprocessor appointment without exiting the service entirely, and that email notification of subprocessor changes requires Customer to affirmatively self-enroll rather than being automatic. The GDPR Article 28(2) framework permits objection rights but does not prescribe the remedy; the termination-only remedy is the contractual implementation of that right....
-
Modal
· Modal Terms of Service
The DPA states that Modal will notify Customer within 48 hours of becoming aware of a data breach affecting Customer Personal Data, providing information sufficient for Customer to meet its own reporting and data subject notification obligations under applicable privacy laws....
Why it matters: This provision establishes a processor-to-controller breach notification timeline of 48 hours, which is shorter than the GDPR's 72-hour controller-to-supervisory-authority window, providing Customer additional time to assess the breach and prepare regulatory notifications. The provision places the obligation to notify data subjects and supervisory authorities on Customer rather than Modal, consistent with the processor-controller relationship....
-
Modal
· Modal Terms of Service
The agreement states that neither party may recover lost profits, business interruption losses, replacement service costs, or other consequential, punitive, or indirect damages from the other, and that total aggregate liability is capped at fees paid or payable under the applicable Service Order in the 12 months preceding the claim....
Why it matters: This provision establishes a mutual cap on aggregate liability equal to 12 months of fees under the applicable Service Order and excludes recovery of consequential and indirect damages by either party. For Customers processing high-value data or running business-critical workloads on the platform, the practical recovery ceiling may be substantially lower than potential operational losses in the event of a service failure or data breach....