-
Sourcegraph Cody
· Sourcegraph Terms of Service
Customers with agreements predating February 15, 2024, or whose order forms explicitly reference the AI Terms of Use, are governed by separate AI-specific terms. All other customers have their AI tool usage governed by the base Terms of Service....
Why it matters: This provision creates two distinct legal frameworks governing AI tool usage depending on agreement execution date, which means enterprise customers may be operating under materially different AI-related obligations, rights, and limitations depending solely on when their agreement was signed....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Security Exhibit applies to all users of generally available Sourcegraph products and governs how Sourcegraph handles User Content, source code, and Confidential Information submitted through the platform....
Why it matters: This provision identifies that source code and Confidential Information processed through Sourcegraph are subject to a dedicated Security Exhibit, which is a material consideration for enterprise customers whose proprietary codebases are processed by the Cody AI assistant....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Data Processing Agreement activates when Sourcegraph processes Customer Personal Data on behalf of a customer, establishing a controller-processor relationship for the purposes of applicable data protection law....
Why it matters: This provision triggers the activation of the Data Processing Agreement when Sourcegraph processes personal data on a customer's behalf, which is a required contractual mechanism under GDPR Article 28 and analogous data protection frameworks for controller-processor relationships....
-
Runway
· Runway Usage Policy
The policy prohibits any content depicting, facilitating, or promoting child sexual abuse or sexualization of minors, requires reporting of CSAM to NCMEC, and states that all accounts associated with CSAM are indefinitely suspended....
Why it matters: This provision reflects mandatory federal reporting obligations under U.S. law for online platforms that become aware of CSAM, and the indefinite suspension of associated accounts represents the most severe enforcement action described in this policy....
-
Runway
· Runway Usage Policy
The policy prohibits using Runway's tools to create or modify non-consensual intimate imagery of real individuals....
Why it matters: This provision addresses a category of AI-generated content that engages a growing body of federal and state legislation specifically targeting AI-generated NCII, including the DEFIANCE Act and numerous state statutes, making this prohibition legally material for both users and the platform....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Runway
· Runway Usage Policy
The policy prohibits using another person's image, video, or audio without their permission as an input or basis for content generation on Runway's platform....
Why it matters: This provision engages right of publicity law, biometric privacy statutes, and personality rights frameworks across multiple jurisdictions, and is operationally relevant for enterprise users generating synthetic media that incorporates real individuals' likenesses or voices....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a commission of 35% of staking rewards earned by standard account holders across supported assets including ETH, SOL, and ADA, with reduced commission rates of 25.25% to 31.75% available to tiered Coinbase One members....
Why it matters: This provision establishes that Coinbase retains 35% of all staking rewards generated for standard users on supported assets, which directly reduces the effective staking yield received by consumers. The tiered Coinbase One commission structure creates a materially different cost basis for subscription members versus non-members....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to make automated decisions that materially and detrimentally affect individual rights in high-risk domains including employment, healthcare, finance, legal matters, housing, insurance, or social welfare, unless human supervision is present....
Why it matters: This provision places a human supervision requirement on institutional deployments of Google generative AI in regulated high-risk domains, creating a user-side compliance obligation that intersects with EU AI Act high-risk system requirements and GDPR Article 22 automated decision-making provisions....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to process personal data or biometric information without obtaining legally required consent, framing this as a violation of others' rights....
Why it matters: This provision places user-side responsibility for ensuring legally required consent when using personal or biometric data as inputs to generative AI, engaging GDPR, CCPA, and state biometric privacy statutes such as Illinois BIPA....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy categorically prohibits generating or distributing content related to child sexual abuse or exploitation through Google's generative AI products....
Why it matters: This provision reflects legal obligations under statutes including the PROTECT Act and COPPA, and aligns with platform liability frameworks under federal law; it is a non-negotiable absolute prohibition with no stated exceptions....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using Google's generative AI to build, generate, or distribute tools or content that enable tracking or monitoring individuals without their consent....
Why it matters: This provision engages privacy law requirements across multiple jurisdictions, including GDPR provisions on lawful data processing, CCPA, and state-level electronic surveillance statutes, placing user-side responsibility for ensuring consent before using generative AI for tracking or monitoring applications....
-
Visa
· Visa Privacy Notice
Visa publishes a separate U.S. Social Security Number Policy and Sensitive Personal Information Statement governing its handling of Social Security numbers and other sensitive personal information categories for U.S. users....
Why it matters: The existence of a dedicated policy for Social Security numbers and sensitive personal information indicates that Visa collects and processes these data categories for at least some U.S. users, which triggers heightened obligations under multiple U.S. state privacy laws and the FTC's Safeguards Rule....
-
StockX
· StockX Privacy Policy
The policy states that StockX has sold or shared personal identifiers, transaction and commercial data, and internet or electronic usage data with advertising and analytics partners and data brokers in the preceding 12 months....
Why it matters: This provision discloses that personal data including identifiers and transaction histories has been transferred to data brokers, a category of recipient that may independently aggregate, re-sell, or further process that data outside StockX's direct control. Under CCPA, this disclosure triggers specific consumer opt-out rights and data broker registration obligations that compliance teams should evaluate....
-
StockX
· StockX Privacy Policy
The policy states that StockX collects facial geometry biometric data through a third-party provider named Persona for identity verification and fraud prevention, with user consent sought prior to collection, and that Persona may use collected biometric data to improve its own verification services....
Why it matters: This provision establishes that biometric facial geometry data is collected by a named third party (Persona) and that Persona retains authority to use that data for its own service improvement purposes, meaning biometric data collected in connection with StockX identity verification may be processed by Persona independently of the original verification purpose. Compliance teams should evaluate whether this arrangement satisfies written consent, retention, and third-party use limitation requirements under applicable biometric privacy statutes....
-
StockX
· StockX Privacy Policy
The CCPA disclosure table states that StockX has collected and shared sensitive personal information including Social Security numbers, VAT identification numbers, tax identification numbers, and government-issued identification numbers with service providers, identity verification providers, business partners, professional advisors, affiliates, and government entities....
Why it matters: This provision discloses that sensitive personal information, including Social Security numbers, is shared with business partners and professional advisors in addition to identity verification and law enforcement contexts. CCPA imposes specific limitations on the use and disclosure of sensitive personal information, and compliance teams should evaluate whether the disclosed sharing practices satisfy CCPA's restrictions on sensitive data processing....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble may sell or share Personal Information as defined under the CCPA in connection with targeted or behavioral advertising, and that users may opt out by emailing Rumble with a specified subject line....
Why it matters: This provision establishes that Rumble's advertising practices may constitute a sale or sharing of Personal Information under the CCPA, triggering opt-out rights for California residents and parallel opt-out obligations under multiple state privacy statutes. The opt-out mechanism is limited to an email request rather than an in-platform toggle, which compliance teams should evaluate against applicable state requirements....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble and its third-party advertising partners may collect and process political opinion data as sensitive personal information for the purpose of providing personalized advertising....
Why it matters: Under GDPR, political opinion data is classified as a special category of personal data subject to heightened processing restrictions and generally requires explicit consent. This provision's authorization of political opinion data processing for advertising purposes may require evaluation against GDPR Article 9 requirements and applicable national implementations across EU member states....
-
Rumble
· Rumble Privacy Policy
The policy states that agreeing to the Privacy Policy constitutes consent to sharing video-viewing activity, video titles, thumbnails, device identifiers, and IP addresses with social networking sites for personalized content and advertising purposes on Rumble and other platforms....
Why it matters: This provision treats agreement to the general Privacy Policy as consent to sharing video-viewing history and identifying data with social networking sites, which may require evaluation under GDPR's consent requirements, including the standards of specificity and granularity, and under the Video Privacy Protection Act (VPPA) in the U.S., which restricts disclosure of video viewing records....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble and third-party advertising partners collect usage activity, device identifiers, unique identifiers, IP addresses, and potentially hashed email addresses, and use this data combined across devices and websites to build behavioral profiles for targeted advertising....
Why it matters: This provision authorizes cross-device and cross-site behavioral profiling for advertising by both Rumble and third-party partners, using data categories including hashed email addresses that may qualify as Personal Information under certain data protection laws. The involvement of third-party advertising partners means data collected on Rumble may be combined with data from other sites those partners operate across....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses that Thomson Reuters collects biometric data including fingerprints and facial geometry scans, and states that such data will be permanently destroyed within the timeframe specified by applicable law or when the collection purpose ends, whichever comes first....
Why it matters: This provision establishes biometric data collection and a destruction schedule tied to legal timelines or cessation of purpose, triggering obligations under the Illinois Biometric Information Privacy Act and analogous statutes in Texas, Washington, and other states that impose specific written consent, retention schedule, and destruction requirements before or at the point of collection....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy states that using or interacting with Thomson Reuters Services constitutes authorization for cross-border transfer of personal data to countries, including the United States, that may offer lesser privacy protections than the user's home country....
Why it matters: This provision asserts that the act of interacting with Services constitutes consent to international data transfers, including to jurisdictions with lower privacy standards. Whether this mechanism satisfies the specificity and granularity requirements of GDPR Article 49 derogations or UK GDPR transfer adequacy provisions warrants regulatory evaluation, as broad behavioral consent embedded in a privacy notice may not meet the standards those frameworks require....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses that Thomson Reuters collects and processes the content of user queries submitted to its Services, explicitly including artificial intelligence prompts, as a category of personal information....
Why it matters: This provision establishes that AI prompt content constitutes a collected personal data category subject to the full range of uses described in the statement, including service improvement, product development, annotating and tagging content, and sharing with third-party business partners. Organizations using Thomson Reuters AI products such as CoCounsel should evaluate whether client-confidential or privileged content submitted as AI prompts is subject to these data handling practices....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses that Thomson Reuters provides services and content incorporating user personal information to third-party customers, including through aggregated listings, reports, profiles, and professional directories, and acknowledges that under certain local laws this may constitute a sale of personal information....
Why it matters: This provision establishes that personal information, including that aggregated from public and private sources into attorney directories and professional profiles, may be made available to all users of Thomson Reuters services and acknowledges that this constitutes a potential sale under applicable law. California residents and residents of other states with sale opt-out rights may exercise those rights, but individuals whose information appears in public records products face a structurally distinct regime governed by the supplemental Public Records Privacy Statement....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses collection of sensitive personal information categories including political and religious beliefs, sexual orientation, racial or ethnic origin, union membership, medical records, disability information, government identifiers such as social security numbers, and passport or driver's license numbers....
Why it matters: This provision establishes that Thomson Reuters collects multiple categories of special category data under GDPR Article 9, sensitive personal information under CCPA/CPRA, and analogously protected categories under other data protection frameworks, each of which imposes heightened lawful basis, consent, and data subject rights requirements beyond those applicable to ordinary personal data....
-
Kick
· Kick Privacy Policy
Creators must provide government-issued identification and tax identification numbers before cashing out earnings or KICKs, with this information collected directly by named and unnamed third-party identity verification providers on Kick's behalf....
Why it matters: This provision establishes a mandatory identity and background check requirement tied to creator payout eligibility, involving collection of government-issued IDs and tax numbers by third-party processors whose identities are not fully disclosed in the provided policy text. This creates a layered data processing structure where sensitive personal data is handled by subprocessors operating under their own terms....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that Whatnot sells and shares personal information with advertising technology companies and advertisers for cross-context behavioral advertising, and provides California residents with a right to opt out of this practice via a designated link....
Why it matters: This provision triggers disclosure, opt-out notice, and Global Privacy Control signal compliance obligations under the California Consumer Privacy Act as amended by the California Privacy Rights Act; the terms authorize ongoing data sharing with advertising and analytics partners unless the user actively exercises the opt-out right....
-
Whatnot
· Whatnot Legal Terms
The policy states that Whatnot collects precise geolocation data from user devices, subject to device-level permission, and uses this data for service delivery, analytics, and advertising purposes....
Why it matters: Precise geolocation constitutes sensitive personal information under CPRA, triggering a separate and distinct opt-out right from the general sale and sharing opt-out; and under GDPR may require explicit consent or a documented legitimate interest assessment depending on the purpose and data flows involved....
-
Whatnot
· Whatnot Legal Terms
The policy authorizes sharing of personal information with advertising partners, analytics providers, and social media companies for targeted advertising and measurement, with those third parties permitted to deploy their own tracking technologies across the user's browsing activity....
Why it matters: This provision authorizes third-party advertising and analytics partners to independently collect user data via tracking technologies deployed across Whatnot's services, which may constitute a sale or sharing of personal information under CCPA/CPRA and requires evaluation under GDPR's lawful basis and ePrivacy consent frameworks....
-
Segment
· Segment Privacy Policy
The notice states that for the Conversational Intelligence service, Twilio processes personal data within voice calls as an independent data controller rather than as a data processor acting under customer instructions....
Why it matters: This provision establishes a distinct legal role for Twilio when processing voice call content through Conversational Intelligence, which affects how data subject rights requests are routed, how liability is allocated between Twilio and its enterprise customers, and what contractual protections apply to this processing outside the standard DPA processor relationship....
-
Checkout.com
· Checkout.com Privacy
The notice authorizes collection of facial images and voice recordings from which biometric identifiers (faceprints, voiceprints, minutiae templates) are extracted for identity verification, with that biometric data shared with Snowflake Computing and Amazon Web Services and retained for up to 365 days before deletion....
Why it matters: This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are operationally significant parameters for compliance with GDPR, UK GDPR, and US state-level biometric privacy statutes that impose consent, disclosure, and retention requirements....
-
Checkout.com
· Checkout.com Privacy
The notice discloses that automated systems may process Merchant Customer data to make fraud detection decisions (potentially declining transactions) and identity verification decisions (potentially delaying or denying product or service access), with affected individuals in certain jurisdictions having the right to request human review of those decisions....
Why it matters: This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be jurisdiction-dependent, meaning not all affected individuals have the same recourse....
-
RunPod
· RunPod Terms of Service
All disputes between users and RunPod must proceed through binding individual arbitration rather than court litigation, and users waive the right to participate in class action lawsuits or class-wide arbitration. Users may opt out of this requirement by submitting written notice within 30 days of accepting the Terms....
Why it matters: This provision requires disputes to proceed through individual binding arbitration and prohibits class or representative actions. The 30-day opt-out window is a time-sensitive contractual deadline that, if missed, applies the arbitration and class waiver provisions to the account going forward....
-
RunPod
· RunPod Terms of Service
RunPod limits its security responsibility to physical infrastructure including hardware, hypervisors, networking equipment, and facilities. Users are contractually responsible for data encryption at rest and in transit, VM guest configuration, OS patching, application security, firewall rules, load balancer settings, object and block storage configuration, and IP and DNS settings....
Why it matters: This provision establishes the contractual boundary of RunPod's security obligations and assigns a defined set of operational security responsibilities to users. Enterprise customers must assess whether their internal security controls and incident response procedures address the user-side obligations enumerated in this clause, particularly where applicable data protection law may impose independent obligations on the data controller....
-
RunPod
· RunPod Terms of Service
By ordering Third-Party Offerings through the Marketplace, users authorize Vendors to access, transmit, modify, delete, or store data on Vendor or third-party systems. RunPod disclaims all responsibility for Vendor data security, privacy practices, and data use, placing sole responsibility on the user for authorizing Vendor data access....
Why it matters: This provision discloses that Third-Party Vendor data practices fall entirely outside RunPod's contractual responsibility. Enterprise customers integrating Marketplace third-party software with data stored on RunPod infrastructure must conduct independent vendor due diligence, as RunPod provides no contractual protection regarding Vendor data handling....
-
AWS Bedrock
· AWS Service Terms
EC2 Reserved Instances, Savings Plans, EC2 Dedicated Host Reservations, and EC2 Capacity Blocks are non-cancellable and non-refundable for the committed term, with charges continuing even if the customer terminates the broader AWS agreement, subject to limited pro rata refund rights if AWS terminates the program....
Why it matters: This provision requires customers to remain financially obligated for the full committed term of Reserved Instances, Savings Plans, Dedicated Hosts, and Capacity Blocks regardless of changes in operational requirements or agreement termination, creating a long-term financial exposure that procurement and finance teams must account for at the point of purchase....
-
AWS Bedrock
· AWS Service Terms
For generative AI services powered by Amazon Bedrock, AWS may process customer content in AWS regions other than the customer's primary region to optimize inference performance, with the specific regions determined by AWS....
Why it matters: This provision authorizes processing of customer content outside the customer's selected AWS region for AI inference workloads, which may engage GDPR Chapter V international transfer restrictions, UK GDPR transfer requirements, and sector-specific data residency obligations depending on the nature of the content and the customer's regulatory environment....
-
AWS Bedrock
· AWS Service Terms
The agreement places full legal responsibility on the customer for providing privacy notices and obtaining consents required by applicable law when processing end user personal data through AWS services, and the customer represents to AWS that these obligations have been met....
Why it matters: This provision establishes that AWS's contractual liability for privacy notice and consent compliance is limited and that the customer assumes responsibility for lawful basis requirements under GDPR, CCPA, and other applicable privacy frameworks when using AWS services to process personal data....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of precise vehicle location data (defined as within a 1,850-foot radius) while a vehicle is in use and upon specified events, with a stated retention period of up to 3 years, and discloses that geolocation collection may continue even after OnStar disconnection under certain emergency or battery-safety conditions....
Why it matters: This provision establishes a data collection practice tied to vehicle operation that persists under specified conditions even after a user takes affirmative steps to disconnect from OnStar or disable location services, creating a documented carve-out that compliance teams should assess against state-level precise geolocation consent requirements....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of AI assistant interaction data including full transcripts, navigation destinations, contacts, call history, and discussion topics from both in-vehicle AI assistants and GM mobile apps, with disclosure limited to service providers acting on GM's behalf and law enforcement under warrant or court order....
Why it matters: This provision establishes a data collection category encompassing conversation transcripts and personal contact data generated through AI assistant use, creating a detailed behavioral and relational data record tied to vehicle and app operation that is subject to government access requests under the policy's stated warrant-or-court-order standard....
-
General Motors
· GM Privacy Statement
The policy discloses that certain data transfers, including identifiers, digital activity information, VIN, and commercial information shared with advertising networks, dealers, and financial institutions, may qualify as 'sales' under applicable state privacy laws, and that consumers may have opt-out rights for these transfers....
Why it matters: This provision identifies specific categories of personal information, including vehicle identification numbers and digital activity data, as potentially sold to third-party advertising and financial partners, triggering opt-out rights under CCPA, CPRA, and analogous state statutes that compliance teams must ensure are operationally satisfied....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of driver behavior data including vehicle speed, braking and acceleration patterns, seatbelt status, and trip duration, and states that this data may be disclosed to General Motors Insurance for usage-based insurance purposes with affirmative consent....
Why it matters: This provision establishes that granular driving behavior metrics may be used to inform insurance rate determinations when the user provides affirmative consent, creating a direct link between vehicle operation data and financial product pricing that has implications for insurance regulatory compliance and consumer disclosure requirements....
-
Ford
· Ford Privacy Policy
The policy states that Ford collects vehicle identification, status, and service history data along with driving behavior data including routes taken, speed, and usage patterns from connected vehicle services....
Why it matters: This provision establishes a continuous data collection relationship between Ford and connected vehicle owners that extends beyond web-based interactions to include real-time operational and behavioral data. Compliance teams should assess whether the scope of this collection and its downstream sharing is adequately disclosed and consented to under applicable state privacy frameworks....
-
Ford
· Ford Privacy Policy
The policy states that Ford collects precise geolocation data through apps, websites, and connected vehicle services, and may share this data with dealers, service providers, and other third parties....
Why it matters: Precise geolocation is classified as sensitive personal information under the CPRA, triggering heightened disclosure, opt-out, and use-limitation obligations for California residents. The authorization to share this data with dealers and unspecified third parties creates a broad distribution pathway for location information....
-
Duolingo
· Duolingo Privacy Policy
This provision authorizes teachers in Duolingo for Schools to access student names, email addresses, learning progress data, and to log in as the student to manage their account. Students can remove teacher access by leaving the classroom in app Settings....
Why it matters: This provision establishes a delegated account access model in which teachers can authenticate as students and access account management functions, which creates data access and identity management considerations under FERPA and applicable state student privacy statutes where school-affiliated accounts involve minors....
-
Walgreens
· Walgreens Privacy Policy
The policy states that Walgreens collects biometric information including facial scans for safety, security, and product feature purposes, and commits to permanently destroying that information either when the original collection purpose is satisfied or within three years of the consumer's last interaction with Walgreens, whichever comes first....
Why it matters: This provision establishes a specific biometric data retention and destruction schedule consistent with requirements under statutes such as the Illinois Biometric Information Privacy Act, which mandates destruction within a specified period. The collection of facial scans for product feature purposes alongside security purposes broadens the stated collection scope beyond traditional loss prevention use cases....
-
Walgreens
· Walgreens Privacy Policy
The policy discloses that health-related retail product purchase data, categorized as Sensitive Personal Information under California law, has been and may continue to be shared with online advertising networks, marketing companies, financial services partners, and social media companies in transactions that may constitute a sale or sharing under the California Consumer Privacy Act....
Why it matters: This provision discloses that health-related retail purchase data is among the categories of Sensitive Personal Information shared with advertising and marketing third parties for secondary purposes, which triggers CPRA opt-out rights for California residents and may require evaluation under CPRA's purpose limitation and sensitive data handling requirements....
-
Walgreens
· Walgreens Privacy Policy
The policy states that Walgreens collects precise location information through satellite, cell phone tower, WiFi, beacons, Bluetooth, and near field communication protocols when location services are enabled on a user's device, and may use Bluetooth signals from the mobile application to determine a user's location within a Walgreens store....
Why it matters: This provision authorizes collection of precise geolocation data through multiple technical mechanisms including in-store Bluetooth positioning, which the policy separately categorizes as Sensitive Personal Information under California law subject to opt-out and heightened handling requirements....
-
Verizon
· Verizon Privacy Policy
The policy discloses that Verizon collects biometric identifiers including voice recordings and voiceprints, along with Social Security Numbers, driver's license numbers, and payment information from customers....
Why it matters: This provision establishes that Verizon's data collection scope includes categories of sensitive personal information, specifically biometric identifiers and government-issued identification numbers, that are subject to heightened protection requirements under multiple state laws including Illinois BIPA, Texas CUBI, and California CPRA....
-
Verizon
· Verizon Privacy Policy
The policy discloses that Verizon installs system software on wireless devices that can automatically install or update applications, collect device and location conditions, and operate on Wi-Fi even when the device is deactivated from the wireless network; some installed apps do not display visible icons....
Why it matters: This provision establishes that Verizon reserves the right to install and maintain software on customer devices that operates independently of active wireless service, including the automatic installation of applications and collection of location and device data, with opt-out limited to disabling notifications from specific management applications....
-
Verizon
· Verizon Privacy Policy
The policy discloses that named Verizon Value brands (Total Wireless, Straight Talk, Tracfone, Simple Mobile, Walmart Family Mobile, Net10 Wireless, Go Smart Mobile, and SafeLink Wireless) share customer-identifying information with Prove, which uses it to assist banks and other third parties in making credit application decisions....
Why it matters: This provision establishes that customer-identifying data from prepaid wireless brands is shared with a third-party partner that uses it in connection with credit application decisioning at financial institutions, creating potential obligations and exposure under the Fair Credit Reporting Act depending on whether these data flows constitute consumer report transactions....