-
Marqeta
· Marqeta Privacy Policy
The document explicitly states that personal data processed in connection with Marqeta's issuer payment processing and card program management services is outside the scope of this Website Privacy Notice and is governed by a separate Services Privacy Notice....
Why it matters: This provision establishes that individuals whose personal data is processed through Marqeta's payment and card program infrastructure are subject to different and separately published privacy terms, which creates a material distinction between the rights and protections described in this notice and those applicable to payment services data subjects....
-
Marqeta
· Marqeta Privacy Policy
The document designates Marqeta Inc. (U.S.), Marqeta UK Ltd., and Marqeta sp. z.o.o. (Poland) as joint data controllers for EEA and UK processing under this notice, with Marqeta U.S. identified as the primary controller responsible for compliance and rights request management....
Why it matters: This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta and its third-party service providers may log session-level behavioral data including clicks, page visits, text entered, and time spent on pages, and that this data may be disclosed to third parties for Marqeta's business purposes including marketing and security....
Why it matters: The explicit reference to logging text entered during sessions is operationally distinct relative to commonly observed tracking disclosures and may encompass form field content entered before submission. The document authorizes disclosure of session-level data to third parties for business purposes, which in combination with the CCPA sale and sharing provision means this data category may be subject to opt-out rights....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta supplements internally collected data with personal data obtained from data providers and aggregators, social media sources, co-branded marketing partners, third-party service providers acting on Marqeta's behalf, and public sources including social networking websites....
Why it matters: The use of data providers and aggregators to supplement first-party data collection is a practice that may require evaluation under applicable law, particularly regarding notice and consent obligations in jurisdictions where data subjects have not directly provided their information to Marqeta. GDPR's transparency requirements under Article 14 apply where personal data is not obtained directly from the data subject....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs may collect personally identifiable information including name, phone number, and postal address, used for purposes of contact and identification....
Why it matters: The provision uses an open-ended 'including but not limited to' formulation that does not limit collection to the listed categories, which means actual data collection could extend beyond name, phone number, and postal address without additional disclosure. Compliance teams should evaluate whether the categories disclosed align with actual data processing activities....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs automatically collects log data on each visit, including IP address, browser version, pages visited, visit timestamps, time spent on pages, and unspecified 'other statistics.'...
Why it matters: IP addresses are classified as personal data under GDPR in the EU, and the inclusion of 'other statistics' creates an open-ended category of automatically collected data that is not bounded by the provision's enumerated examples. The policy does not state a retention period for log data....
-
Modal
· Modal Privacy Policy
The policy states that unspecified third-party companies and individuals engaged by Modal Labs for service facilitation, delivery, and analytics are granted access to users' personal information, subject to an obligation not to use or disclose it beyond their assigned tasks....
Why it matters: The provision does not identify the third parties receiving personal data, does not describe the contractual mechanism through which the stated obligation is enforced, and does not specify which categories of personal data are shared with which categories of third parties. This structure may be insufficient to satisfy GDPR processor agreement requirements or CCPA disclosure obligations for categories of third parties to whom personal information is disclosed....
-
Modal
· Modal Privacy Policy
The policy states that modal.com uses cookies to collect information and improve the service, that users may accept or refuse cookies through browser settings, and that refusing cookies may result in limited access to some portions of the service....
Why it matters: The provision does not identify the specific cookies used, distinguish between functional and tracking cookies, or describe what information is collected through cookies, which may be insufficient under EU ePrivacy Directive and GDPR cookie consent requirements applicable to EU users....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs may update the privacy policy at any time, that changes take effect immediately upon posting, and that notification is provided solely by posting the updated policy on the same page....
Why it matters: The provision establishes that policy changes become effective immediately upon posting without advance notice, email notification, or a defined review period, which may be inconsistent with GDPR requirements for meaningful notification of material changes to data processing terms and may limit users' practical ability to respond to changes before they take effect....
-
Modal
· Modal Privacy Policy
The policy states that Modal Labs uses commercially acceptable means to protect personal information but does not guarantee absolute security against data breaches or unauthorized access....
Why it matters: The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insufficient to satisfy GDPR's requirement for appropriate technical and organizational security measures....
-
Modal
· Modal Terms of Service
The agreement states that minimum fee commitments in Service Orders are based on the service tier purchased rather than actual usage, are non-cancelable during the term, and are not refundable except in the limited termination scenarios described in section 3.2....
Why it matters: This provision establishes that Customers are financially obligated for the full committed service term and amount regardless of whether they use the Service, creating a fixed cost exposure that does not vary with actual consumption. The only exception pathways are those described in the termination section, which require material breach or specified insolvency events....
-
Modal
· Modal Terms of Service
The agreement states that Modal will not use Customer Data to train AI models or ingest Customer Data into large language models without the Customer's prior written consent, and that Input and Output from AI Tools are classified as Customer Data....
Why it matters: This provision establishes a contractual prohibition on AI model training using Customer Data as a default, requiring affirmative written consent before any such use. Because Input and Output are classified as Customer Data, this prohibition extends to materials submitted to and generated by Modal's AI Tools....
-
Modal
· Modal Terms of Service
The agreement states that Customer grants Modal a perpetual, irrevocable, worldwide, sublicensable, royalty-free license to use Feedback for any purpose, with an exclusion for Customer Data and Customer Confidential Information contained in the Feedback....
Why it matters: This provision establishes that any suggestions, comments, or other feedback submitted by Customer to Modal are subject to a broad, perpetual, and irrevocable license that cannot be withdrawn, and that Modal may sublicense and transfer this rights grant to third parties. The exclusion for Customer Data and Confidential Information contained in Feedback provides a carveout, but the boundary between Feedback and embedded Customer Data may require assessment in practice....
-
Modal
· Modal Terms of Service
The agreement states that Modal may collect and use aggregate or permanently anonymized usage data for its own business purposes both during and after the agreement term, and that this right survives termination. The definition of Service Metrics requires that the data not identify an individual or Customer and that technical safeguards against reidentification be in place....
Why it matters: This provision establishes a post-termination data retention and use right for Modal covering aggregate and anonymized usage data, which operates as an exception to the general data deletion obligations upon termination. The enforceability of the anonymization standard as a basis for excluding this data from privacy law obligations depends on the robustness of the anonymization and reidentification safeguards, which the agreement states are implemented but does not detail in the main terms....
-
Modal
· Modal Terms of Service
The DPA states that Modal will provide 30 days advance notice of subprocessor changes via website update and email notification (if Customer has self-enrolled), but that the only available remedy for a Customer objection to a new subprocessor is termination of the subscription....
Why it matters: This provision establishes that Customer cannot block a new subprocessor appointment without exiting the service entirely, and that email notification of subprocessor changes requires Customer to affirmatively self-enroll rather than being automatic. The GDPR Article 28(2) framework permits objection rights but does not prescribe the remedy; the termination-only remedy is the contractual implementation of that right....
-
Modal
· Modal Terms of Service
The DPA states that Modal will notify Customer within 48 hours of becoming aware of a data breach affecting Customer Personal Data, providing information sufficient for Customer to meet its own reporting and data subject notification obligations under applicable privacy laws....
Why it matters: This provision establishes a processor-to-controller breach notification timeline of 48 hours, which is shorter than the GDPR's 72-hour controller-to-supervisory-authority window, providing Customer additional time to assess the breach and prepare regulatory notifications. The provision places the obligation to notify data subjects and supervisory authorities on Customer rather than Modal, consistent with the processor-controller relationship....
-
Modal
· Modal Terms of Service
The agreement states that neither party may recover lost profits, business interruption losses, replacement service costs, or other consequential, punitive, or indirect damages from the other, and that total aggregate liability is capped at fees paid or payable under the applicable Service Order in the 12 months preceding the claim....
Why it matters: This provision establishes a mutual cap on aggregate liability equal to 12 months of fees under the applicable Service Order and excludes recovery of consequential and indirect damages by either party. For Customers processing high-value data or running business-critical workloads on the platform, the practical recovery ceiling may be substantially lower than potential operational losses in the event of a service failure or data breach....
-
Modal
· Modal Terms of Service
The agreement states that Customer is solely responsible for Customer Data and must defend and indemnify Modal against third-party claims alleging intellectual property infringement, misappropriation, or violation of applicable law related to Customer Data....
Why it matters: This provision establishes that Customer bears the full defense and indemnification burden for any third-party claims arising from Customer Data, including claims that Customer Data infringes third-party intellectual property rights or violates applicable law. Because Input and Output from AI Tools are classified as Customer Data, this obligation extends to AI-generated outputs that Customer uses....
-
Modal
· Modal Terms of Service
The DPA states that Modal will not transfer EEA or UK Personal Data outside those regions without Customer consent or a compliant transfer mechanism, and that Customer consents in advance to transfers where Modal has implemented GDPR or UK GDPR-compliant safeguards including SCCs, adequacy decisions, or Article 46 safeguards....
Why it matters: This provision establishes the legal basis for cross-border personal data transfers by Modal, incorporating EU SCCs (Modules 1-3), UK IDTA, and Swiss law provisions by reference into the DPA. The advance consent mechanism for GDPR-compliant transfers means Customers do not need to separately authorize each transfer where Modal has implemented the specified safeguards....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy expressly states that it does not create contractual or other legal rights for any party, including users, which the company may assert to limit claims based on the Policy's stated data practices....
Why it matters: This provision asserts that the Privacy Policy does not establish enforceable rights or contractual obligations, which may be cited by the company in response to user claims arising from data handling practices described in the document. Whether this disclaimer is effective as a bar to claims under applicable state and federal consumer privacy statutes is a legal question not resolved by the document alone....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that tracking technologies may be used to automatically log users back into their accounts when returning to the Online Services, and places responsibility on users to affirmatively log out to prevent other device users from accessing their account and personal information....
Why it matters: This provision establishes an automatic login mechanism for accounts that may contain health plan information, medical records, and financial data, and states that users who do not affirmatively log out accept responsibility for unauthorized access by other users of their devices. The allocation of security responsibility to users in the context of health data access warrants review against HIPAA access control and minimum necessary standards....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that UnitedHealthcare may combine information collected through Online Services with offline data from internal and vendor sources and use or disclose the combined dataset for the purposes described in the Policy or for internal business purposes....
Why it matters: This provision authorizes data aggregation across online behavioral data, health and medical information, financial data, and offline records from vendors, which may produce enriched data profiles extending beyond what users submit directly through Online Services. The permissibility of such combination involving Protected Health Information is subject to HIPAA's minimum necessary and permissible use standards....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy establishes a process for California residents to request disclosure of the categories of personal information shared with third parties for direct marketing purposes and the identities of those third parties, limited to one request per calendar year submitted in writing....
Why it matters: This provision addresses California's Shine the Light statute obligations but does not address California Consumer Privacy Act rights such as the right to know, right to delete, or right to opt out of sale or sharing of personal information for cross-context behavioral advertising. The scope of California privacy rights described in this Policy may not fully reflect the company's obligations under current California law....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that the mobile application may collect health and medical information, financial information, GPS and network-based location data, and user files including calendars, photos, and videos from users' devices, subject to device-level permission grants....
Why it matters: This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collected through a mobile application associated with health insurance services. The collection of device files and location data beyond what is necessary for navigation or core health services functionality may require evaluation against applicable data minimization principles and HIPAA minimum necessary standards where health data is involved....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy discloses that UnitedHealthcare does not honor web browser Do Not Track signals, citing the absence of a common definition and industry-accepted standards for such signals....
Why it matters: This provision discloses the company's non-compliance with browser-level Do Not Track signals in the context of a platform that collects health, financial, and behavioral data. Several US state privacy laws, including California's, require disclosure of Do Not Track response practices, which this provision satisfies as a disclosure obligation. The Global Privacy Control signal, which some states require platforms to honor as an opt-out of sale or sharing mechanism, is not addressed in this provision....
-
Experian
· Experian Privacy Policy
The notice states that Experian does not collect sensitive personal information from consumers in seventeen named states, and that the sensitive personal information data practices disclosed in the notice apply only to consumers in states not included in that list. This creates a tiered data collection structure based on state of residence....
Why it matters: This provision establishes a geographic differentiation in Experian's sensitive personal information collection practices, with consumers in seventeen named states excluded from the collection and sale of sensitive data categories as described in the notice. Compliance teams should evaluate what operational mechanisms Experian uses to determine and enforce state-of-residence-based data collection restrictions at the point of collection....
-
Experian
· Experian Privacy Policy
The notice establishes opt-out rights covering the sale and sharing of personal information and use for targeted advertising, available to consumers in applicable states, and states that the opt-out does not affect credit report data or credit scores. Opt-out requests do not require identity verification and can be submitted online, by mail, or by email....
Why it matters: This provision establishes the scope and mechanism of consumer opt-out rights, including the specific clarification that profiling for legal or significant effects is not offered as an opt-out option because Experian asserts it does not engage in such profiling. The document's note that opt-out settings are linked to current address means that consumers who relocate may need to resubmit requests, creating an ongoing maintenance obligation for consumers who want their opt-out to remain effective....
-
Experian
· Experian Privacy Policy
The notice states that Experian accepts Global Privacy Control signals as opt-out requests in states where applicable, but that the opt-out is linked only to the browser identifier unless the consumer separately connects it to their account or personal information held by Experian. Consumers must enable the GPC signal on each browser or extension they use individually....
Why it matters: This provision establishes that GPC-based opt-outs operate at the browser identifier level and do not automatically extend to a consumer's full Experian account or other personal information records unless the consumer takes an additional step to link them by contacting Experian. This creates an operational gap where a consumer who relies solely on GPC may have their browsing-derived data opted out but their account-level personal information and data broker records continue to be sold....
-
Experian
· Experian Privacy Policy
The notice states that when Experian processes personal information on behalf of business clients, it acts as a processor or service provider, and that the client's privacy notice and contractual agreement govern that processing rather than this notice. Consumers seeking rights related to such data must contact the business client, not Experian directly....
Why it matters: This provision establishes a dual-role framework under which Experian may operate as either a data controller or a processor depending on the context, and directs consumers to the relevant business client for rights requests when Experian acts in a processor capacity. This affects the practical pathway for consumers seeking to exercise access, deletion, or correction rights with respect to data Experian processes on behalf of third-party clients....
-
Experian
· Experian Privacy Policy
The notice states that personal information is retained for as long as necessary to provide services or fulfill stated purposes, and may also be retained for legal compliance, dispute resolution, fraud prevention, and rights enforcement. No specific retention periods or timelines are stated....
Why it matters: This provision establishes that retention periods are not fixed and may vary by data category, product, and purpose, without specifying maximum retention durations. The absence of stated retention timelines limits consumers' ability to assess how long specific categories of personal information, including sensitive categories such as Social Security numbers and racial or ethnic origin data, are held by Experian....
-
Harvey AI
· Harvey AI Privacy Policy
The privacy policy explicitly excludes documents uploaded to the platform, AI inputs, and AI outputs from its scope. Those categories are governed by the Customer Agreement between Harvey and the employing organization, and data subject requests for that content must be directed to the employer, not Harvey....
Why it matters: This provision establishes a structural bifurcation of data controller and data processor responsibilities that directly determines the path for data subject rights requests. End users whose employers are Harvey Customers may find that their rights regarding platform-submitted content must be exercised through their employer rather than through Harvey's publicly disclosed privacy mechanisms....
-
Harvey AI
· Harvey AI Privacy Policy
The policy states Harvey does not sell personal data for payment but acknowledges that sharing data with advertising partners, analytics providers, and social networks for targeted advertising purposes may qualify as a sale or sharing under the CCPA. An opt-out mechanism is available under 'Your Privacy Choices' on the Harvey website....
Why it matters: This provision creates an operational CCPA compliance obligation requiring a functioning opt-out mechanism for targeted advertising data flows. The terms authorize disclosure of website visitor Personal Data to advertising, analytics, and social network partners, and the document acknowledges this may trigger CCPA sale or sharing definitions, which require California residents to be provided with an accessible opt-out pathway....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey has certified participation in the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks, and in the event of conflict between this policy and DPF Principles, the DPF Principles take precedence. The FTC holds enforcement jurisdiction over Harvey's DPF compliance commitments....
Why it matters: DPF certification establishes the legal transfer mechanism for Personal Data flowing from the EU, UK, and Switzerland to Harvey's US servers, and the provision states that DPF Principles override conflicting policy language. This creates a defined enforcement pathway through the FTC for EU, UK, and Swiss data subjects with unresolved complaints....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey collects publicly available information, including court judgments, decisions, and public filings, and uses this information to develop, train, and improve its AI platform. This category of information is listed as a data source across multiple processing purposes throughout the policy....
Why it matters: This provision authorizes the use of publicly available legal and professional documents as AI training data, which engages questions about whether individuals named in such documents have any practical control over their inclusion in training datasets. The policy links to a separate page providing additional detail on training data sources and privacy impact minimization steps....
-
Harvey AI
· Harvey AI Privacy Policy
In the event of a business reorganization including a sale, merger, or asset transfer, Harvey may disclose Personal Data to counterparties during due diligence and transfer it to a successor entity. The terms state Harvey will notify users if it intends to transfer their information....
Why it matters: This provision authorizes disclosure of Personal Data to third-party counterparties during due diligence processes before any transaction is completed. The notification commitment is stated but does not specify a timeline, method, or minimum notice period, which may affect practical enforceability of the notification right....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey receives Personal Data about individuals from third-party marketing vendors, advertising vendors including social media services, and market research firms and event organizers. This information includes contact details, professional affiliations, employment information, and behavioral data about interactions with Harvey's marketing materials and advertisements....
Why it matters: This provision establishes that Harvey collects Personal Data about individuals who have not directly interacted with Harvey, sourced from third-party marketing vendors, research firms, and event organizers. This category of indirect data collection may affect individuals who are not aware they are in Harvey's data ecosystem....
-
Together AI
· Together AI Privacy Policy
The policy states that Together AI will not use collected user data, including submitted prompts and content, to train its AI models unless the user has explicitly opted in; users may revoke this consent at any time and request deletion of collected data....
Why it matters: This provision establishes a consent-based restriction on a core commercial use of user-submitted data in AI development contexts. The opt-in framing represents a specific commitment that may require evaluation against operational data pipeline practices, particularly for third-party service providers receiving user data....
-
Together AI
· Together AI Privacy Policy
The Zero Data Retention mode, enabled through Privacy and Security settings, prevents submitted content including texts, images, and prompts, as well as model outputs, from being stored or used for secondary purposes; however, once enabled, the company states it cannot subsequently access, retrieve, correct, export, or delete that data on the user's behalf....
Why it matters: This provision creates a technical and contractual limitation on the company's ability to fulfill data subject rights requests for data processed under ZDR, which may require evaluation under GDPR Articles 15, 16, 17, and 20 to assess whether the architecture is consistent with data subject rights obligations or whether supplemental disclosures are required....
-
Together AI
· Together AI Privacy Policy
The policy states that Personal Data may be transferred to and processed in jurisdictions outside the user's own, including jurisdictions with different data protection standards, and characterizes policy acceptance as agreement to such transfer; the European section additionally identifies standard contractual clauses as the transfer safeguard for EEA, Swiss, and UK users....
Why it matters: The consent-as-transfer-mechanism framing for general users may require evaluation under GDPR, where valid cross-border transfer requires specific legal mechanisms under Chapter V rather than general policy acceptance; the policy separately identifies standard contractual clauses for EEA, Swiss, and UK users, which is the operative transfer mechanism for those populations....
-
Together AI
· Together AI Privacy Policy
The policy authorizes use and transfer of Personal Data, including as a business asset, in connection with mergers, acquisitions, divestitures, restructurings, dissolutions, bankruptcy proceedings, or similar transactions....
Why it matters: This provision authorizes Personal Data to be transferred to a successor entity in a corporate transaction without requiring individual user consent for that specific transfer, which is a standard but operationally significant commercial term affecting how user data may be handled following a change of corporate control....
-
Together AI
· Together AI Privacy Policy
The policy affirms that Together AI does not currently sell Personal Data as defined under the CCPA, commits to providing prior notice and opt-out rights if that practice changes, and establishes a deletion right for California residents exercisable by verifiable request to privacy@together.ai with a 45-day response window....
Why it matters: The explicit non-sale affirmation is a material CCPA compliance disclosure; the commitment to provide notice and opt-out rights before any future sale establishes a procedural obligation that would apply if business practices change. The 45-day response timeline with a permissible 90-day extension is consistent with CCPA statutory requirements....
-
Together AI
· Together AI Privacy Policy
For users in the EEA, Switzerland, and the UK, the policy enumerates data subject rights including access, correction, deletion, objection, processing restriction, and portability, exercisable through account settings or by contacting privacy@together.ai, along with the right to lodge a complaint with a data protection authority....
Why it matters: This provision establishes the operational rights framework for GDPR-covered users and identifies the contact mechanism for exercising rights not available through account settings; the consent withdrawal provision clarifies that prior processing based on consent remains lawful after withdrawal, consistent with GDPR Article 7(3)....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy reserves ActiveCampaign's right to restrict or prohibit content or accounts in industries including cryptocurrency, digital assets, and financial services based on its sole discretion determination of objectionability, reputational risk, or non-compliance with applicable law....
Why it matters: This clause establishes eligibility criteria for platform access that are not defined by objective thresholds, granting ActiveCampaign unilateral authority to restrict or terminate service to customers in designated industry verticals without defined notice, appeal, or cure mechanisms stated in this policy....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy requires customers to independently verify opt-in consent for every marketing message recipient and explicitly prohibits using business card contacts as a valid consent mechanism....
Why it matters: This provision places affirmative opt-in verification obligations on customers, aligning with TCPA, CAN-SPAM, and CASL requirements, and establishes that failure to comply exposes customers to account suspension and carrier or regulatory penalties rather than creating any ActiveCampaign compliance obligation....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy prohibits customers from sending marketing messages to contacts obtained through paid or rented lists and prohibits use of the platform to distribute content through list brokers of any form....
Why it matters: This provision establishes that use of purchased or rented contact lists through the platform constitutes a policy violation, which could trigger account suspension under the general enforcement provisions of this policy. This restriction directly affects customers who rely on third-party data providers or list acquisition as a lead generation strategy....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy reserves ActiveCampaign's right to modify the AUP at any time without customer consent, with notice provided by email, in-platform notification, or date update, and continued platform use constitutes acceptance of revised terms....
Why it matters: This clause establishes that continued use of the platform following any form of notice constitutes binding acceptance of revised terms, including changes that could alter permitted use categories, restricted industries, or enforcement mechanisms. A date update at the top of the document is stated to constitute sufficient notice....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy states that ActiveCampaign continuously monitors customer activity, transmitted content, and recipient engagement metrics including bounce, abuse, and unsubscribe rates, and reserves the right to delete content and trigger manual account review based on these metrics....
Why it matters: This clause establishes that ActiveCampaign conducts ongoing automated monitoring of both customer-side activity and recipient-side engagement data, with unilateral authority to remove content and initiate account review based on metric thresholds that are not defined in the policy....
-
ConvertKit
· ConvertKit Acceptable Use Policy
The policy includes, as a prohibited category, any content that Kit determines at its discretion to be potentially harmful or misleading, without defining criteria for that determination....
Why it matters: This provision reserves to Kit open-ended enforcement authority over content that does not fall within enumerated prohibited categories, based on an undefined standard of 'potentially harmful or misleading' content....
-
ConvertKit
· ConvertKit Acceptable Use Policy
The policy requires senders to hold documented proof of permission for every subscriber, either through direct opt-in or through a purchase made within the preceding 12 months where email consent was obtained at the point of sale....
Why it matters: This provision establishes a platform-level permission standard that requires documented proof of consent for each subscriber, and limits purchase-based consent to a 12-month window, creating an ongoing compliance obligation for list hygiene and consent record-keeping....
-
ConvertKit
· ConvertKit Acceptable Use Policy
Kit states that it continuously monitors account-level email performance metrics including bounce rates, spam complaint rates, and unsubscribe rates, and that elevated metrics may trigger manual review, account suspension, or termination, with no refund or data export entitlement upon closure....
Why it matters: This provision establishes that ongoing platform access is contingent on maintaining acceptable email performance metrics as assessed by Kit, with termination consequences and no data portability entitlement applying to accounts closed for performance-related reasons....