-
Modal
· Modal Terms of Service
The agreement states that California law governs all disputes, and that exclusive jurisdiction is vested in the federal courts of the Northern District of California and the state courts of California. Both parties consent to this jurisdiction and waive forum non conveniens challenges....
Why it matters: This provision establishes that all disputes must be litigated in California courts under California law, regardless of where the Customer is located or incorporated. The forum non conveniens waiver means Customers cannot seek to transfer proceedings to a more convenient or locally accessible court....
-
Modal
· Modal Terms of Service
The agreement states that Customer is solely responsible for Customer Data and must defend and indemnify Modal against third-party claims alleging intellectual property infringement, misappropriation, or violation of applicable law related to Customer Data....
Why it matters: This provision establishes that Customer bears the full defense and indemnification burden for any third-party claims arising from Customer Data, including claims that Customer Data infringes third-party intellectual property rights or violates applicable law. Because Input and Output from AI Tools are classified as Customer Data, this obligation extends to AI-generated outputs that Customer uses....
-
Modal
· Modal Terms of Service
The DPA states that Modal will not transfer EEA or UK Personal Data outside those regions without Customer consent or a compliant transfer mechanism, and that Customer consents in advance to transfers where Modal has implemented GDPR or UK GDPR-compliant safeguards including SCCs, adequacy decisions, or Article 46 safeguards....
Why it matters: This provision establishes the legal basis for cross-border personal data transfers by Modal, incorporating EU SCCs (Modules 1-3), UK IDTA, and Swiss law provisions by reference into the DPA. The advance consent mechanism for GDPR-compliant transfers means Customers do not need to separately authorize each transfer where Modal has implemented the specified safeguards....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that UnitedHealthcare may modify its terms at any time by posting updates to the Policy page, and that continued use of the Online Services constitutes consent to those changes without any requirement for individual notice or affirmative opt-in....
Why it matters: This provision establishes a unilateral change mechanism under which the data practices governing health, financial, and behavioral information may be altered without advance individual notification, with consent implied through continued service use. The absence of a notice requirement or affirmative consent mechanism may require evaluation under FTC guidance on material changes to privacy policies and applicable state consumer protection statutes....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy discloses that electronic communications sent to users may contain Protected Health Information and may be transmitted without encryption, and states that users acknowledge and accept the associated risk of disclosure or interception....
Why it matters: This provision requires evaluation under the HIPAA Security Rule and Breach Notification Rule, which establish standards for the protection of electronic Protected Health Information in transmission. The assertion that user acknowledgment and acceptance of interception risk limits the company's obligations in this context is not established by the document and may conflict with HIPAA's minimum necessary and safeguard requirements....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy expressly states that it does not create contractual or other legal rights for any party, including users, which the company may assert to limit claims based on the Policy's stated data practices....
Why it matters: This provision asserts that the Privacy Policy does not establish enforceable rights or contractual obligations, which may be cited by the company in response to user claims arising from data handling practices described in the document. Whether this disclaimer is effective as a bar to claims under applicable state and federal consumer privacy statutes is a legal question not resolved by the document alone....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy authorizes third parties to use cookies and tracking technologies on UnitedHealthcare's Online Services to collect browsing activity and track users across third-party websites for the purpose of delivering targeted advertisements, with the company stating it does not control these third-party technologies....
Why it matters: This provision authorizes cross-site behavioral tracking and targeted advertising on digital properties through which users may also access health plan information, benefit details, and medical records. The intersection of behavioral advertising data collection with a health insurance platform context may require evaluation under HIPAA, FTC guidance on health data, and state consumer privacy laws depending on the categories of data accessible to or inferred by third-party trackers....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that tracking technologies may be used to automatically log users back into their accounts when returning to the Online Services, and places responsibility on users to affirmatively log out to prevent other device users from accessing their account and personal information....
Why it matters: This provision establishes an automatic login mechanism for accounts that may contain health plan information, medical records, and financial data, and states that users who do not affirmatively log out accept responsibility for unauthorized access by other users of their devices. The allocation of security responsibility to users in the context of health data access warrants review against HIPAA access control and minimum necessary standards....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that UnitedHealthcare may combine information collected through Online Services with offline data from internal and vendor sources and use or disclose the combined dataset for the purposes described in the Policy or for internal business purposes....
Why it matters: This provision authorizes data aggregation across online behavioral data, health and medical information, financial data, and offline records from vendors, which may produce enriched data profiles extending beyond what users submit directly through Online Services. The permissibility of such combination involving Protected Health Information is subject to HIPAA's minimum necessary and permissible use standards....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy establishes a process for California residents to request disclosure of the categories of personal information shared with third parties for direct marketing purposes and the identities of those third parties, limited to one request per calendar year submitted in writing....
Why it matters: This provision addresses California's Shine the Light statute obligations but does not address California Consumer Privacy Act rights such as the right to know, right to delete, or right to opt out of sale or sharing of personal information for cross-context behavioral advertising. The scope of California privacy rights described in this Policy may not fully reflect the company's obligations under current California law....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that the mobile application may collect health and medical information, financial information, GPS and network-based location data, and user files including calendars, photos, and videos from users' devices, subject to device-level permission grants....
Why it matters: This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collected through a mobile application associated with health insurance services. The collection of device files and location data beyond what is necessary for navigation or core health services functionality may require evaluation against applicable data minimization principles and HIPAA minimum necessary standards where health data is involved....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that UnitedHealthcare will not intentionally collect personal information from children under 13 without parental consent, consistent with COPPA requirements, and provides a mechanism for reporting suspected under-13 data collection....
Why it matters: This provision establishes COPPA compliance intent for Online Services that may be accessed by minors in the context of family health plan management or dependent benefit access. The qualifier 'intentionally' in the collection restriction, rather than an absolute prohibition, reflects standard COPPA framing but leaves open the question of how unintentional under-13 data collection would be identified and addressed operationally....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy discloses that UnitedHealthcare does not honor web browser Do Not Track signals, citing the absence of a common definition and industry-accepted standards for such signals....
Why it matters: This provision discloses the company's non-compliance with browser-level Do Not Track signals in the context of a platform that collects health, financial, and behavioral data. Several US state privacy laws, including California's, require disclosure of Do Not Track response practices, which this provision satisfies as a disclosure obligation. The Global Privacy Control signal, which some states require platforms to honor as an opt-out of sale or sharing mechanism, is not addressed in this provision....
-
Experian
· Experian Privacy Policy
The notice discloses that Experian has sold or disclosed sensitive personal information categories, including Social Security numbers, driver's license numbers, financial account credentials combined with access codes, precise geolocation, and racial or ethnic origin data, to third parties across more than twenty industry categories for commercial purposes including marketing, analytics, and decisioning. These third-party categories include political organizations, marketing and research companies, insurance companies, and financial services companies....
Why it matters: This provision establishes that Experian's data broker subsidiaries have sold or disclosed sensitive personal information categories, some of which are subject to heightened protections or opt-in consent requirements under multiple state privacy laws, to a broad range of commercial third parties. Compliance teams should evaluate whether the opt-out mechanism described in the notice satisfies applicable requirements for each sensitive data category in each covered jurisdiction, particularly where state law may require affirmative opt-in consent for the sale or processing of categories such as racial or ethnic origin, precise geolocation, or financial account credentials....
-
Experian
· Experian Privacy Policy
The notice states that Experian does not collect sensitive personal information from consumers in seventeen named states, and that the sensitive personal information data practices disclosed in the notice apply only to consumers in states not included in that list. This creates a tiered data collection structure based on state of residence....
Why it matters: This provision establishes a geographic differentiation in Experian's sensitive personal information collection practices, with consumers in seventeen named states excluded from the collection and sale of sensitive data categories as described in the notice. Compliance teams should evaluate what operational mechanisms Experian uses to determine and enforce state-of-residence-based data collection restrictions at the point of collection....
-
Experian
· Experian Privacy Policy
The notice establishes opt-out rights covering the sale and sharing of personal information and use for targeted advertising, available to consumers in applicable states, and states that the opt-out does not affect credit report data or credit scores. Opt-out requests do not require identity verification and can be submitted online, by mail, or by email....
Why it matters: This provision establishes the scope and mechanism of consumer opt-out rights, including the specific clarification that profiling for legal or significant effects is not offered as an opt-out option because Experian asserts it does not engage in such profiling. The document's note that opt-out settings are linked to current address means that consumers who relocate may need to resubmit requests, creating an ongoing maintenance obligation for consumers who want their opt-out to remain effective....
-
Experian
· Experian Privacy Policy
The notice states that Experian accepts Global Privacy Control signals as opt-out requests in states where applicable, but that the opt-out is linked only to the browser identifier unless the consumer separately connects it to their account or personal information held by Experian. Consumers must enable the GPC signal on each browser or extension they use individually....
Why it matters: This provision establishes that GPC-based opt-outs operate at the browser identifier level and do not automatically extend to a consumer's full Experian account or other personal information records unless the consumer takes an additional step to link them by contacting Experian. This creates an operational gap where a consumer who relies solely on GPC may have their browsing-derived data opted out but their account-level personal information and data broker records continue to be sold....
-
Experian
· Experian Privacy Policy
The notice discloses that three named Experian subsidiaries are registered data brokers under Texas law and have registered with the Texas Secretary of State as required to conduct business in Texas. This disclosure is stated in both capitalized and standard text formats....
Why it matters: This provision reflects a mandatory disclosure obligation under the Texas Data Privacy and Security Act and Texas data broker registration requirements. The registration creates a public compliance record with the Texas Secretary of State that is accessible to consumers and regulators....
-
Experian
· Experian Privacy Policy
The notice states that when Experian processes personal information on behalf of business clients, it acts as a processor or service provider, and that the client's privacy notice and contractual agreement govern that processing rather than this notice. Consumers seeking rights related to such data must contact the business client, not Experian directly....
Why it matters: This provision establishes a dual-role framework under which Experian may operate as either a data controller or a processor depending on the context, and directs consumers to the relevant business client for rights requests when Experian acts in a processor capacity. This affects the practical pathway for consumers seeking to exercise access, deletion, or correction rights with respect to data Experian processes on behalf of third-party clients....
-
Experian
· Experian Privacy Policy
The notice discloses CCPA-required annual metrics for the 2025 calendar year, showing that Experian received and fully complied with 1,127 deletion requests, 274 correction requests, 704 access requests, 4,700 opt-out of sale/sharing requests, and 4,660 requests to limit sensitive personal information use, with average response times ranging from approximately 2.1 to 2.3 days and zero requests denied due to inability to verify consumer identity....
Why it matters: This provision constitutes a mandatory CCPA compliance disclosure and provides a quantitative record of Experian's rights request processing performance for the 2025 calendar year. The disclosure of full compliance with all received requests and sub-three-day average response times establishes a documented performance baseline that may be referenced in regulatory reviews or compliance audits....
-
Experian
· Experian Privacy Policy
The notice states that personal information is retained for as long as necessary to provide services or fulfill stated purposes, and may also be retained for legal compliance, dispute resolution, fraud prevention, and rights enforcement. No specific retention periods or timelines are stated....
Why it matters: This provision establishes that retention periods are not fixed and may vary by data category, product, and purpose, without specifying maximum retention durations. The absence of stated retention timelines limits consumers' ability to assess how long specific categories of personal information, including sensitive categories such as Social Security numbers and racial or ethnic origin data, are held by Experian....
-
Experian
· Experian Privacy Policy
The notice states that Experian does not collect, sell, share, or disclose personal information of individuals under 16 years of age....
Why it matters: This provision establishes a categorical prohibition on data collection and sale for minors under 16, which aligns with the CCPA's prohibition on selling personal information of minors under 16 without affirmative authorization. No mechanism is described for age verification or for addressing cases where a minor's data may have been collected without Experian's knowledge....
-
Harvey AI
· Harvey AI Privacy Policy
The privacy policy explicitly excludes documents uploaded to the platform, AI inputs, and AI outputs from its scope. Those categories are governed by the Customer Agreement between Harvey and the employing organization, and data subject requests for that content must be directed to the employer, not Harvey....
Why it matters: This provision establishes a structural bifurcation of data controller and data processor responsibilities that directly determines the path for data subject rights requests. End users whose employers are Harvey Customers may find that their rights regarding platform-submitted content must be exercised through their employer rather than through Harvey's publicly disclosed privacy mechanisms....
-
Harvey AI
· Harvey AI Privacy Policy
The policy states Harvey does not sell personal data for payment but acknowledges that sharing data with advertising partners, analytics providers, and social networks for targeted advertising purposes may qualify as a sale or sharing under the CCPA. An opt-out mechanism is available under 'Your Privacy Choices' on the Harvey website....
Why it matters: This provision creates an operational CCPA compliance obligation requiring a functioning opt-out mechanism for targeted advertising data flows. The terms authorize disclosure of website visitor Personal Data to advertising, analytics, and social network partners, and the document acknowledges this may trigger CCPA sale or sharing definitions, which require California residents to be provided with an accessible opt-out pathway....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey has certified participation in the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks, and in the event of conflict between this policy and DPF Principles, the DPF Principles take precedence. The FTC holds enforcement jurisdiction over Harvey's DPF compliance commitments....
Why it matters: DPF certification establishes the legal transfer mechanism for Personal Data flowing from the EU, UK, and Switzerland to Harvey's US servers, and the provision states that DPF Principles override conflicting policy language. This creates a defined enforcement pathway through the FTC for EU, UK, and Swiss data subjects with unresolved complaints....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey collects publicly available information, including court judgments, decisions, and public filings, and uses this information to develop, train, and improve its AI platform. This category of information is listed as a data source across multiple processing purposes throughout the policy....
Why it matters: This provision authorizes the use of publicly available legal and professional documents as AI training data, which engages questions about whether individuals named in such documents have any practical control over their inclusion in training datasets. The policy links to a separate page providing additional detail on training data sources and privacy impact minimization steps....
-
Harvey AI
· Harvey AI Privacy Policy
In the event of a business reorganization including a sale, merger, or asset transfer, Harvey may disclose Personal Data to counterparties during due diligence and transfer it to a successor entity. The terms state Harvey will notify users if it intends to transfer their information....
Why it matters: This provision authorizes disclosure of Personal Data to third-party counterparties during due diligence processes before any transaction is completed. The notification commitment is stated but does not specify a timeline, method, or minimum notice period, which may affect practical enforceability of the notification right....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey receives Personal Data about individuals from third-party marketing vendors, advertising vendors including social media services, and market research firms and event organizers. This information includes contact details, professional affiliations, employment information, and behavioral data about interactions with Harvey's marketing materials and advertisements....
Why it matters: This provision establishes that Harvey collects Personal Data about individuals who have not directly interacted with Harvey, sourced from third-party marketing vendors, research firms, and event organizers. This category of indirect data collection may affect individuals who are not aware they are in Harvey's data ecosystem....
-
Harvey AI
· Harvey AI Privacy Policy
The policy discloses that individuals may access, correct, update, delete, object to, restrict, or request portability of their Personal Data, subject to legal exceptions. Users may also opt out of marketing emails and complain to a supervisory authority. These rights are exercised by contacting privacy@harvey.ai....
Why it matters: This provision establishes the available data subject rights mechanisms and confirms access to regulatory complaint channels including EU DPAs and the UK ICO. The rights are subject to exceptions and exemptions, and the scope of available rights varies by jurisdiction as described in the Jurisdiction Specific Provisions section....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey retains Personal Data for as long as necessary for the described purposes, including legal obligations, dispute resolution, agreement enforcement, and tax and audit requirements. Data held in backup archives that cannot be immediately deleted is stored securely and isolated from further processing until deletion is possible....
Why it matters: The retention period for end users whose employers hold a Customer Agreement is governed by that agreement rather than solely by this policy, creating a dependency on enterprise contract terms for determining how long individual user data is held. The backup archive carve-out for data that cannot be immediately deleted is a standard but operationally relevant provision for deletion request management....
-
Together AI
· Together AI Privacy Policy
The policy states that Together AI will not use collected user data, including submitted prompts and content, to train its AI models unless the user has explicitly opted in; users may revoke this consent at any time and request deletion of collected data....
Why it matters: This provision establishes a consent-based restriction on a core commercial use of user-submitted data in AI development contexts. The opt-in framing represents a specific commitment that may require evaluation against operational data pipeline practices, particularly for third-party service providers receiving user data....
-
Together AI
· Together AI Privacy Policy
The Zero Data Retention mode, enabled through Privacy and Security settings, prevents submitted content including texts, images, and prompts, as well as model outputs, from being stored or used for secondary purposes; however, once enabled, the company states it cannot subsequently access, retrieve, correct, export, or delete that data on the user's behalf....
Why it matters: This provision creates a technical and contractual limitation on the company's ability to fulfill data subject rights requests for data processed under ZDR, which may require evaluation under GDPR Articles 15, 16, 17, and 20 to assess whether the architecture is consistent with data subject rights obligations or whether supplemental disclosures are required....
-
Together AI
· Together AI Privacy Policy
The policy states that Together AI will notify users and provide a copy of any law enforcement request for their Personal Data, unless legally prohibited from doing so, such as by a court-imposed gag order or applicable legal restriction....
Why it matters: This provision establishes a transparency commitment regarding government data requests that is operationally distinct from policies that provide no such notification; the practical scope of this commitment depends on the frequency and legal constraints applicable to law enforcement requests received....
-
Together AI
· Together AI Privacy Policy
The policy states that Personal Data may be transferred to and processed in jurisdictions outside the user's own, including jurisdictions with different data protection standards, and characterizes policy acceptance as agreement to such transfer; the European section additionally identifies standard contractual clauses as the transfer safeguard for EEA, Swiss, and UK users....
Why it matters: The consent-as-transfer-mechanism framing for general users may require evaluation under GDPR, where valid cross-border transfer requires specific legal mechanisms under Chapter V rather than general policy acceptance; the policy separately identifies standard contractual clauses for EEA, Swiss, and UK users, which is the operative transfer mechanism for those populations....
-
Together AI
· Together AI Privacy Policy
The policy authorizes use and transfer of Personal Data, including as a business asset, in connection with mergers, acquisitions, divestitures, restructurings, dissolutions, bankruptcy proceedings, or similar transactions....
Why it matters: This provision authorizes Personal Data to be transferred to a successor entity in a corporate transaction without requiring individual user consent for that specific transfer, which is a standard but operationally significant commercial term affecting how user data may be handled following a change of corporate control....
-
Together AI
· Together AI Privacy Policy
The policy affirms that Together AI does not currently sell Personal Data as defined under the CCPA, commits to providing prior notice and opt-out rights if that practice changes, and establishes a deletion right for California residents exercisable by verifiable request to privacy@together.ai with a 45-day response window....
Why it matters: The explicit non-sale affirmation is a material CCPA compliance disclosure; the commitment to provide notice and opt-out rights before any future sale establishes a procedural obligation that would apply if business practices change. The 45-day response timeline with a permissible 90-day extension is consistent with CCPA statutory requirements....
-
Together AI
· Together AI Privacy Policy
For users in the EEA, Switzerland, and the UK, the policy enumerates data subject rights including access, correction, deletion, objection, processing restriction, and portability, exercisable through account settings or by contacting privacy@together.ai, along with the right to lodge a complaint with a data protection authority....
Why it matters: This provision establishes the operational rights framework for GDPR-covered users and identifies the contact mechanism for exercising rights not available through account settings; the consent withdrawal provision clarifies that prior processing based on consent remains lawful after withdrawal, consistent with GDPR Article 7(3)....
-
Together AI
· Together AI Privacy Policy
The policy states that Together AI's services are not directed to users under age 13, that the company does not knowingly collect Personal Data from that age group, and that discovered data collected from under-13 users without verified parental consent will be removed from servers....
Why it matters: This provision establishes COPPA-aligned age restriction and data removal commitments; the absence of a defined response timeline for parental notification or removal requests may warrant operational clarification....
-
Together AI
· Together AI Privacy Policy
The policy states that updates may be made at any time and will be effective when posted; direct notification to users is conditioned on a legal requirement to do so, and the policy advises users who find changes unacceptable to cease using the service....
Why it matters: The notification mechanism is conditional on legal obligation rather than a proactive commitment to direct user notice, meaning users bear responsibility for monitoring the policy page for changes absent a legal notification trigger. Under GDPR, material changes to processing purposes or legal bases may require active notification and, in consent-based processing, fresh consent....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy states that ActiveCampaign may immediately suspend or terminate a customer's account upon receiving spam or unsolicited message complaints from recipients, and that no refund of any kind will be provided in such circumstances....
Why it matters: This clause establishes that account termination can occur immediately upon complaint, without a documented cure period or internal dispute process, and that prepaid service fees are forfeited under these conditions. The operational dependency risk is significant for businesses relying on ActiveCampaign as a primary marketing channel....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy reserves ActiveCampaign's right to restrict or prohibit content or accounts in industries including cryptocurrency, digital assets, and financial services based on its sole discretion determination of objectionability, reputational risk, or non-compliance with applicable law....
Why it matters: This clause establishes eligibility criteria for platform access that are not defined by objective thresholds, granting ActiveCampaign unilateral authority to restrict or terminate service to customers in designated industry verticals without defined notice, appeal, or cure mechanisms stated in this policy....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy requires customers to independently verify opt-in consent for every marketing message recipient and explicitly prohibits using business card contacts as a valid consent mechanism....
Why it matters: This provision places affirmative opt-in verification obligations on customers, aligning with TCPA, CAN-SPAM, and CASL requirements, and establishes that failure to comply exposes customers to account suspension and carrier or regulatory penalties rather than creating any ActiveCampaign compliance obligation....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy warns customers that non-compliant SMS and text messaging may result in fines of up to $10,000 per violation assessed by mobile carriers, citing increased regulation of SMS messaging....
Why it matters: This provision discloses a specific per-violation financial penalty figure associated with SMS non-compliance, placing customers on notice of the financial exposure associated with CTIA guideline violations and directing them to comply with referenced CTIA standards as a condition of platform use....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy prohibits customers from sending marketing messages to contacts obtained through paid or rented lists and prohibits use of the platform to distribute content through list brokers of any form....
Why it matters: This provision establishes that use of purchased or rented contact lists through the platform constitutes a policy violation, which could trigger account suspension under the general enforcement provisions of this policy. This restriction directly affects customers who rely on third-party data providers or list acquisition as a lead generation strategy....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy reserves ActiveCampaign's right to modify the AUP at any time without customer consent, with notice provided by email, in-platform notification, or date update, and continued platform use constitutes acceptance of revised terms....
Why it matters: This clause establishes that continued use of the platform following any form of notice constitutes binding acceptance of revised terms, including changes that could alter permitted use categories, restricted industries, or enforcement mechanisms. A date update at the top of the document is stated to constitute sufficient notice....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy states that ActiveCampaign continuously monitors customer activity, transmitted content, and recipient engagement metrics including bounce, abuse, and unsubscribe rates, and reserves the right to delete content and trigger manual account review based on these metrics....
Why it matters: This clause establishes that ActiveCampaign conducts ongoing automated monitoring of both customer-side activity and recipient-side engagement data, with unilateral authority to remove content and initiate account review based on metric thresholds that are not defined in the policy....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy explicitly prohibits use of ActiveCampaign's SMS and messaging services for emergency alerts, disaster notifications, or health and safety threat communications including terrorism, natural disasters, or emergency response....
Why it matters: This clause establishes a specific operational limitation on the permitted use of ActiveCampaign's messaging infrastructure, which is operationally significant for any organization that manages emergency communications or public safety notification workflows alongside marketing operations....
-
ConvertKit
· ConvertKit Acceptable Use Policy
The policy states that accounts found in violation of prohibited content or conduct terms may be closed immediately without advance notice, with no refund issued and data export subject to Kit's sole discretion....
Why it matters: This provision establishes that Kit may terminate account access and withhold both payment refunds and subscriber data export without prior notification, creating material operational exposure for businesses that rely on the platform for active campaigns and subscriber list management....
-
ConvertKit
· ConvertKit Acceptable Use Policy
The policy includes, as a prohibited category, any content that Kit determines at its discretion to be potentially harmful or misleading, without defining criteria for that determination....
Why it matters: This provision reserves to Kit open-ended enforcement authority over content that does not fall within enumerated prohibited categories, based on an undefined standard of 'potentially harmful or misleading' content....
-
ConvertKit
· ConvertKit Acceptable Use Policy
The policy requires senders to hold documented proof of permission for every subscriber, either through direct opt-in or through a purchase made within the preceding 12 months where email consent was obtained at the point of sale....
Why it matters: This provision establishes a platform-level permission standard that requires documented proof of consent for each subscriber, and limits purchase-based consent to a 12-month window, creating an ongoing compliance obligation for list hygiene and consent record-keeping....