-
Uniswap
· Uniswap Privacy Policy
The policy discloses CCPA rights for California residents including data access, copy, and deletion requests submitted to privacy@uniswap.org, and states that Uniswap Labs will verify the identity of requesters before responding and will only fulfill requests where it can associate submitted identifying details with held information using reasonable effort....
Why it matters: This provision establishes the CCPA rights framework applicable to California residents and conditions fulfillment of data requests on identity verification and the company's ability to associate provided identifiers with held data. Given the policy's stated practice of not collecting names or IP addresses, the practical scope of fulfillable CCPA requests may be limited....
-
Uniswap
· Uniswap Privacy Policy
The policy states four GDPR lawful bases for processing EU user data: consent, contract performance, legal obligation, and legitimate interests. It also enumerates GDPR rights including access, rectification, erasure, objection, restriction, and portability, exercisable by contacting privacy@uniswap.org....
Why it matters: This provision establishes the GDPR compliance framework for EU data subjects and invokes legitimate interests as one of four processing bases without specifying the particular processing activities to which each basis applies, which may require evaluation under applicable supervisory authority guidance on documentation of legitimate interests assessments....
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs may transfer or share collected data to another entity in connection with a merger, acquisition, bankruptcy, dissolution, reorganization, asset or stock sale, or other business transaction....
Why it matters: This provision reserves the right to transfer user data, including wallet addresses, device data, and any other collected information, to a successor or acquiring entity in a broad range of corporate transactions, without specifying user notification procedures or consent requirements for such transfers....
-
Uniswap
· Uniswap Privacy Policy
The policy states that material changes will be notified via the Services, and that continued use of the Services constitutes consent to the updated policy terms....
Why it matters: This provision conditions consent to policy changes on continued use of the Services following in-app notification, without specifying a minimum notice period before changes take effect or a separate affirmative consent mechanism for material changes....
-
Uniswap
· Uniswap Privacy Policy
The policy states that the Services are not directed at children, that Uniswap Labs does not knowingly collect personal information from children as defined by COPPA, and provides a contact address for reporting potential child data collection....
Why it matters: This provision establishes a COPPA compliance representation and sets the reporting mechanism for child data concerns, though the policy applies the under-18 threshold rather than COPPA's statutory under-13 threshold, which may reflect a broader internal policy choice....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs does not share user information with any third parties for marketing purposes....
Why it matters: This provision establishes an explicit prohibition on sharing user data for third-party marketing, which is a specific and unqualified representation that may be assessed against actual data flows to advertising and analytics providers described elsewhere in the policy....
-
ConvertKit
· ConvertKit Terms of Service
The document footer references a dedicated GDPR page, indicating that Kit maintains separate GDPR-specific documentation addressing EU data protection obligations applicable to users in the EU and EEA....
Why it matters: This provision signals that Kit asserts GDPR compliance and directs EU users to a companion document, which may contain data processing terms, lawful basis disclosures, and data subject rights procedures relevant to institutional compliance assessments....
-
ConvertKit
· ConvertKit Terms of Service
The document footer references a Privacy Policy as a companion document, indicating that data collection, use, and sharing practices are governed by a separate policy document linked from the platform....
Why it matters: Privacy policies incorporated by reference into terms of service form part of the overall contractual framework; the specific data types collected, sharing authorizations, and user rights established by Kit's Privacy Policy govern the data relationship between Kit and its users....
-
ConvertKit
· ConvertKit Terms of Service
The document describes platform features including paid newsletter subscriptions, digital product sales with transaction fees, newsletter sponsorships, and paid recommendations, indicating that Kit's terms govern commercial transactions conducted through the platform....
Why it matters: Platform-mediated commerce features including paid newsletters and digital product sales are subject to terms governing transaction fees, payout eligibility, and seller obligations that have direct financial implications for creator accounts....
-
ConvertKit
· ConvertKit Terms of Service
The document states that the platform formerly operated as ConvertKit and is now branded as Kit, indicating a corporate rebranding that may affect how existing contractual relationships, data processing agreements, and service terms are referenced by prior account holders....
Why it matters: A platform rebranding can affect the legal entity name under which terms are entered, the continuity of existing Data Processing Agreements referencing the prior entity name, and the enforceability of terms accepted under the prior brand identity....
-
ConvertKit
· ConvertKit Terms of Service
The platform describes advertiser participation and newsletter sponsorship features, indicating that terms governing advertiser relationships, sponsored content placements, and sponsorship payment structures are part of the platform's operative terms....
Why it matters: Advertiser and sponsorship terms establish the conditions under which sponsored content is placed within creator newsletters, including advertiser eligibility, content restrictions, payment terms, and disclosure obligations that may engage FTC endorsement guidelines....
-
23andMe
· 23andMe Privacy Statement
The agreement states that users who opt into research participation have their deidentified genetic data combined with data from other research participants, and that opt-out from this program is available at any time....
Why it matters: This provision establishes the mechanism by which genetic information, once deidentified by 23andMe's processes, is aggregated into research datasets. The adequacy of the deidentification standard applied and the identity of downstream research partners are not detailed in this excerpt, which are material considerations under GDPR, HIPAA, and California GIPA transparency requirements....
-
23andMe
· 23andMe Privacy Statement
The agreement states that account deletion triggers automatic research opt-out and physical sample discard, and that neither the deletion process nor a prior sample discard choice can be reversed or cancelled....
Why it matters: This provision establishes an irreversible operational workflow for account and biological sample deletion, which has direct implications for data subject rights requests under GDPR Article 17 and CCPA deletion request compliance, as well as for users who may wish to restore access or retrieve data after deletion....
-
23andMe
· 23andMe Privacy Statement
The agreement states that users may elect whether their biological DNA sample is stored after laboratory processing, and that a choice to discard the sample is irreversible....
Why it matters: This provision establishes that the storage or destruction of biological genetic material is a one-time irreversible election, which affects users' ability to request future sample-based testing or retrieval of physical genetic material....
-
23andMe
· 23andMe Privacy Statement
The agreement states that users of Telehealth Services coordinated through 23andMe are subject to a separate Medical Record Privacy Notice governing medical information, distinct from this general Privacy Statement....
Why it matters: This provision establishes that Telehealth users operate under a layered notice architecture, where medical information is governed by a separate document not fully incorporated into this Privacy Statement. Compliance assessment of medical data handling requires review of both documents....
-
23andMe
· 23andMe Privacy Statement
The agreement states that participation in sharing features, including DNA Relatives and Your Connections, is a voluntary user election rather than a default setting....
Why it matters: This provision establishes that genetic relationship data disclosed through features such as DNA Relatives is shared only upon affirmative user participation, which has implications for the genetic privacy of both the opting-in user and any biological relatives whose identities may be inferred from shared genetic data....
-
23andMe
· 23andMe Privacy Statement
The agreement states that 23andMe accounts are protected with two-factor authentication as a standard security measure....
Why it matters: This provision establishes two-factor authentication as a baseline account security control for a platform holding sensitive genetic and health-related data, which is relevant to regulatory expectations under GDPR Article 32 and FTC data security guidelines....
-
23andMe
· 23andMe Privacy Statement
The document references separate regional privacy notices for EEA, UK, and Switzerland users, indicating that the full privacy framework for these user populations is governed by documents beyond this Privacy Statement....
Why it matters: This provision indicates that the privacy terms applicable to EU, UK, and Swiss users are contained in separate regional notices, which means this Privacy Statement alone does not constitute the complete disclosure for those populations. Compliance assessment for these regions requires review of the referenced regional notices....
-
Windsurf
· Windsurf Security & Data Handling
The document states that user data is used for model training by default, with a self-service opt-out available to paid plan users through the Data Controls settings page; on the Teams plan, only administrators may exercise this opt-out....
Why it matters: This provision establishes a default opt-in structure for model training across non-enterprise paid tiers, requiring affirmative action by the user or administrator to disable. The tiered access to the opt-out mechanism (individual paid users versus Teams administrators) creates a differentiated data governance structure that organizations must account for in their internal access and consent workflows....
-
Windsurf
· Windsurf Security & Data Handling
The document states that enterprise customers are subject to a stricter standard under which Cognition will not use their data for model training without express prior written consent, with specific terms deferred to the individual enterprise agreement....
Why it matters: This provision establishes a higher consent threshold for enterprise customers relative to other paid tiers, requiring affirmative written authorization before any training use. The deferral to individual enterprise agreements means the specific scope and enforceability of this commitment may vary by contract....
-
Windsurf
· Windsurf Security & Data Handling
The document states that while general customer data is retained for the duration of the customer relationship, Feedback Data and User Interaction Data are retained for an unspecified period determined solely by Cognition....
Why it matters: This provision creates a carve-out for two categories of data (Feedback Data and User Interaction Data) from the general customer relationship-duration retention standard, with no defined maximum retention period. The retention duration for these categories is governed entirely by Cognition's internal determination....
-
Windsurf
· Windsurf Security & Data Handling
The document states that output produced by Devin is treated as the user's intellectual property for commercial purposes, subject to a restriction prohibiting use of that output to train models that reverse engineer or compete with Devin....
Why it matters: This provision asserts a use restriction on output that would otherwise be characterized as user-owned intellectual property. The restriction on training competing models using Devin output may require legal evaluation in open-source deployment contexts or where users intend to develop adjacent AI tooling....
-
Windsurf
· Windsurf Security & Data Handling
The document states that users may configure and limit which GitHub repositories Devin can access, with permissions manageable through GitHub's App Settings before and after installation....
Why it matters: This provision establishes that source code repository access is configurable by the user, placing responsibility for access scope management with the customer. The document references a GitHub Integration Guide for detailed permission and security information but does not enumerate specific permissions granted by default....
-
Windsurf
· Windsurf Security & Data Handling
The document states that the Slack integration is limited to processing only data explicitly provided in Slack threads where Devin is tagged, with no access to broader Slack instance data....
Why it matters: This provision defines the data minimization scope of the Slack integration, limiting Devin's data access to thread-specific interactions. This disclosure is operationally relevant for organizations concerned about Devin accessing broader Slack workspace data....
-
Windsurf
· Windsurf Security & Data Handling
The document discloses that Cognition obtained SOC 2 Type II certification in March 2024, covering security policies, procedures, and controls related to data security, privacy, processing integrity, confidentiality, and availability....
Why it matters: The SOC 2 Type II certification provides a third-party audit attestation of Cognition's security controls across the five trust service criteria, which is a commonly required vendor security credential for enterprise procurement. The document references a Trust Center for additional detail but does not provide the certification report or audit period directly....
-
Windsurf
· Windsurf Security & Data Handling
The document advises users to store credentials such as passwords, API keys, and cookies through the Secrets feature in Settings rather than sharing them directly in prompts or sessions....
Why it matters: This provision places responsibility on users to manage credential security by directing them to a specific product feature. The document frames this as advisory guidance rather than a platform-enforced restriction, meaning users who share credentials outside the Secrets feature do so outside the recommended security perimeter....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document states, in response to the FAQ question, that GitHub does not use Copilot Business or Enterprise customer data to train AI models....
Why it matters: This provision is the most operationally significant data use commitment on the Trust Center page for enterprise customers, as it defines the boundary of how prompt and engagement data submitted through Business and Enterprise tiers may be used by GitHub....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document identifies four categories of data processed by Copilot: AI-generated suggestions, user feedback including reactions and support ticket feedback, user prompts and associated context, and pseudonymous engagement data including accepted/dismissed completions, error messages, system logs, and product usage metrics....
Why it matters: This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot....
-
GitHub
· GitHub Copilot Business Privacy Statement
GitHub states it has achieved ISO/IEC 42001:2023 certification, an international standard for AI management systems, and is extending this certification across the GitHub Copilot portfolio, applying consistent governance controls across developer productivity, enterprise workflow, and custom agent use cases....
Why it matters: This provision documents GitHub's stated compliance with ISO/IEC 42001:2023, which is the primary international standard for AI management systems and a certification increasingly referenced in enterprise procurement requirements and EU AI Act readiness assessments....
-
GitHub
· GitHub Copilot Business Privacy Statement
GitHub displays a warning on GitHub.com when a file contains hidden Unicode text, which the document states can cause code to appear differently in a user interface than it is interpreted or compiled, including by AI systems....
Why it matters: This provision discloses a platform-level security control implemented on GitHub.com that is operationally relevant to organizations using Copilot, as hidden Unicode characters in code files can alter AI-generated suggestions or code interpretation in ways not visible in standard views....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document discloses that GitHub Copilot holds SOC 1 Type 2, SOC 2 Type 2, SOC 3, ISO 27001:2013, CSA STAR Level 2, TISAX, and ISO/IEC 42001:2023 certifications, and makes audit reports and bridge letters available through the Trust Center....
Why it matters: The availability of SOC 2 Type 2 and SOC 1 Type 2 reports, including bridge letters covering December 2025, provides enterprise procurement and compliance teams with independently audited evidence of Copilot's operational security and availability controls....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document states that GitHub Copilot includes an AI-based vulnerability prevention system that blocks insecure coding patterns in real time, operating on Azure infrastructure with encryption....
Why it matters: This provision discloses a real-time AI content moderation mechanism within Copilot that filters code suggestions, which is operationally relevant to security teams assessing the reliability and scope of Copilot's security controls in development workflows....
-
Arlo
· Arlo Terms of Service
The Arlo website uses Google's reCAPTCHA service on at least its email sign-up form, and the agreement states that Google's Privacy Policy and Terms of Service apply in connection with that feature....
Why it matters: This disclosure establishes that users interacting with the reCAPTCHA-protected form are subject to Google's Privacy Policy and Terms of Service in addition to Arlo's own terms, creating a third-party data processing relationship that compliance teams may need to account for in data mapping and consent frameworks....
-
DraftKings
· DraftKings Terms of Use
The agreement requires users to resolve disputes with DraftKings through individual binding arbitration administered under JAMS rules, waiving the right to jury trial and participation in class or collective actions. A 30-day opt-out window is available from the date of first use or account creation....
Why it matters: This provision requires that disputes between users and DraftKings proceed through individual arbitration rather than court proceedings, and prohibits participation in class or collective actions. The 30-day opt-out window is the operative mechanism for users who wish to preserve court access....
-
DraftKings
· DraftKings Terms of Use
The agreement caps DraftKings total financial liability to any individual user at $100 for all damages, losses, or causes of action combined, regardless of the nature or amount of the claim....
Why it matters: This provision establishes a $100 ceiling on all recoverable damages from DraftKings in connection with platform use, contest participation, account actions, or website operations, applicable to all causes of action collectively....
-
DraftKings
· DraftKings Terms of Use
The agreement states that player deposits and winnings are held in a segregated bank account controlled by DK Player Reserve LLC, a separate DraftKings subsidiary, and asserts that these funds are not available to DraftKings Inc. creditors. The terms prohibit commingling of DraftKings Inc. funds with the segregated player funds....
Why it matters: This provision establishes the structural mechanism for player fund protection, asserting that user deposits and winnings are held in a legally distinct entity and are insulated from DraftKings Inc. creditor claims. The operational and legal effectiveness of this structure depends on applicable state regulatory requirements and the corporate separateness of DK Player Reserve LLC....
-
DraftKings
· DraftKings Terms of Use
The agreement reserves to DraftKings sole and absolute discretion the authority to withhold or revoke prizes, require additional releases as conditions of payout, deny participation in head-to-head contests, and invalidate contest results. Account termination may occur without prior notice....
Why it matters: This provision authorizes DraftKings to withhold prizes, require release of claims as a condition of payment, and terminate accounts without advance notice, with decisions described as final and binding. The breadth of sole discretion authority over prize withholding and account standing creates material financial exposure for users....
-
DraftKings
· DraftKings Terms of Use
The agreement authorizes DraftKings and its affiliates to transfer, allocate, or apply user account funds across affiliated platforms and services subject to applicable law and location-based restrictions. The terms note that deposited funds may not always be transferable depending on the user's physical location....
Why it matters: This provision grants DraftKings and its affiliates authorization to move user account funds across multiple platforms and services, with restrictions that vary by location. The operational scope of this authorization depends on which affiliated platforms and services are in scope at any given time....
-
DraftKings
· DraftKings Terms of Use
By entering a contest or accepting a prize, users agree to indemnify DraftKings and its affiliates from all liability, claims, and actions arising from contest participation, prize use or misuse, travel to prize-related activities, and claims based on publicity rights, defamation, or invasion of privacy....
Why it matters: This provision requires users to hold DraftKings harmless from a broad range of claims arising from contest participation and prize activities, including personal injury, property damage, and privacy-related claims. The indemnification obligation is triggered by contest entry or prize acceptance....
-
DraftKings
· DraftKings Terms of Use
The agreement requires users to certify under penalty of perjury the accuracy of their taxpayer identification number, backup withholding status, U.S. person status, and any FATCA exemption codes provided. Users consent to receive tax documents including Forms 1099 and W-2G electronically through the player account page....
Why it matters: This provision imposes a perjury-certified tax certification obligation on users as part of account registration and prize participation, engaging IRS reporting requirements for fantasy sports winnings. The electronic tax document consent governs delivery of Forms 1099 and W-2G, which are required for user income tax reporting....
-
DraftKings
· DraftKings Terms of Use
The agreement states that all payments are final and no refunds will be issued. If a deposit is charged back, all winnings generated from that deposit are invalidated and forfeited, the original deposit amount is deducted from the account balance, and DraftKings may close the account without notice....
Why it matters: This provision establishes a no-refund policy for all deposits and authorizes DraftKings to forfeit winnings, deduct the original deposit, and close the account without notice if a chargeback is processed on any deposit....
-
DraftKings
· DraftKings Terms of Use
The agreement restricts contest participation to users physically located outside specified excluded states and Louisiana parishes, and prohibits use of virtual private networks or any means of disguising physical location while using the platform. Use of a VPN constitutes a terms violation....
Why it matters: This provision establishes physical location verification as an eligibility condition and prohibits VPN use as a mechanism to circumvent geographic restrictions. Violation of the VPN prohibition constitutes a terms breach that may trigger account enforcement actions....
-
Ticketmaster
· Ticketmaster Terms of Use
The agreement requires all disputes between users and Ticketmaster or Live Nation to be resolved through binding individual arbitration administered by JAMS, waiving both jury trial rights and the ability to participate in class action proceedings, with limited exceptions for small claims court....
Why it matters: This provision establishes JAMS individual arbitration as the exclusive dispute resolution mechanism for all claims not already filed before August 12, 2025, and applies to all products and services sold through or by Ticketmaster regardless of when the underlying dispute arose. The clause expressly invokes the Federal Arbitration Act, designates federal law as governing, and excludes state arbitration laws from applying....
-
Ticketmaster
· Ticketmaster Terms of Use
By submitting any content to the Ticketmaster or Live Nation Marketplace, users grant a perpetual, irrevocable, worldwide, royalty-free, sublicensable license to use, reproduce, modify, distribute, and incorporate that content into advertisements and other works, and to pass those rights to third parties....
Why it matters: This provision establishes that user-submitted content, including photos, reviews, or other materials, may be used by Ticketmaster and Live Nation in advertising and distributed to third parties under sublicensed rights, with no time limitation and no compensation obligation. The scope of the license, including advertising incorporation and irrevocable third-party sublicensing, may require evaluation under GDPR consent requirements and California right-of-publicity statutes for affected user groups....
-
Ticketmaster
· Ticketmaster Terms of Use
The agreement limits Ticketmaster's total liability per user to the greater of $100 or amounts paid in the prior 12 months, excludes all indirect, incidental, punitive, and consequential damages, and includes a broad waiver of personal injury and death claims including those arising from communicable disease contracted at an event....
Why it matters: This provision establishes a monetary ceiling on all claims against Ticketmaster and Live Nation, including claims arising from ticket purchases, marketplace use, and event attendance, and asserts a pre-event waiver of personal injury and wrongful death claims on behalf of both the user and any accompanying minor. The personal injury and death waiver, and the waiver on behalf of accompanying minors, may face enforceability constraints in jurisdictions that limit pre-event liability waivers or prohibit parents from waiving minors' claims....
-
Ticketmaster
· Ticketmaster Terms of Use
The agreement authorizes Ticketmaster to terminate or suspend accounts at any time for any reason, cancel existing orders and tickets, and deny future access, and specifies that users may not receive refunds for fees related to tickets canceled due to code of conduct violations....
Why it matters: This provision establishes that account termination for code of conduct violations may result in ticket cancellation without refund, and that Ticketmaster may take enforcement action against accounts it believes are associated with a violating user even without confirmed identity of that user. The broad 'for any reason' termination right, combined with the no-refund consequence for conduct violations, creates material financial exposure for consumers whose accounts are terminated....
-
Ticketmaster
· Ticketmaster Terms of Use
Before commencing arbitration or filing in small claims court, users must send a written notice to disputes@ticketmaster.com with specified account and claim information, then participate in a teleconference or videoconference within 60 days; only after completing this process may arbitration be initiated....
Why it matters: This provision establishes a mandatory procedural prerequisite to arbitration that requires personal participation in a teleconference or videoconference meet-and-confer, with a 60-day window, before any formal claim may be filed. The statute of limitations tolling provision during this period is operationally significant for users managing time-sensitive claims....
-
Ticketmaster
· Ticketmaster Terms of Use
When 75 or more similar arbitration demands are filed by claimants represented by the same or coordinating law firms, the claims are processed under JAMS Mass Arbitration Procedures, with aggregate consumer filing fees capped at $2,500 and a JAMS Process Administrator overseeing preliminary matters....
Why it matters: This provision establishes a distinct procedural track for coordinated consumer claims that meet the 75-demand threshold, which may affect the pace and structure of resolution for large-scale consumer disputes. The aggregate $2,500 consumer fee cap in mass arbitration contexts is operationally distinct from the $250 per-claimant filing fee applicable to individual arbitrations....
-
Ticketmaster
· Ticketmaster Terms of Use
Users must defend and indemnify Ticketmaster, its officers, directors, agents, event organizers, suppliers, advertisers, and sponsors against all claims, damages, and legal fees arising from the user's misuse of the Marketplace, third-party rights violations, negligence, or terms violations....
Why it matters: This provision extends the user's indemnification obligation to cover event organizers, suppliers, advertisers, and sponsors in addition to Ticketmaster itself, and grants Ticketmaster the right to assume exclusive control of any covered claim and require user cooperation in mounting defenses. The breadth of covered parties and Ticketmaster's right to control defense strategy are operationally significant for users who may face third-party claims....
-
Ticketmaster
· Ticketmaster Terms of Use
Users who opt into mobile messaging authorize Ticketmaster to send recurring automated marketing messages to their mobile number, and separately authorize their wireless carrier to disclose account and device information to Ticketmaster for identity verification and fraud investigation purposes....
Why it matters: The provision includes an authorization for wireless carriers to disclose user account and device information to Ticketmaster, which is a disclosure mechanism distinct from Ticketmaster's own data collection and may not be prominently visible to users who enroll in mobile messaging primarily for event alerts. The opt-out process specifies up to 10 days for removal from the messaging database....