-
Verizon
· Verizon Privacy Policy
The policy authorizes disclosure of email addresses, purchase history, and site and app activity to third-party advertising and analytics companies, which may use this data to create persistent cross-platform identifiers associated with customers, their households, or their devices, and may combine it with data from other sources for targeted advertising and audience matching....
Why it matters: This provision authorizes disclosure of personally identifying information including email addresses to third-party advertising companies for cross-platform identifier creation and audience matching, a practice that extends data use beyond Verizon's own platforms and involves third parties combining Verizon customer data with independently collected data....
-
T-Mobile
· T-Mobile Privacy Policy
Upon opt-in, T-Mobile and its partners analyze app usage, purchase history, browsing activity, precise location, and CPNI to create audience segments and insights, which may be shared with third-party brands for targeted advertising and campaign measurement....
Why it matters: This provision establishes that CPNI, which is subject to FCC regulatory protections under the Communications Act, is combined with precise location, browsing activity, and purchase data for advertising purposes upon opt-in, and that resulting audience segments and ad IDs may be shared with external brand partners....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement discloses a broad list of sensitive personal data categories collected, including Social Security numbers, biometric data, precise location, text message content, and children's data, and states that without consent these categories are not used for characteristic inference or sold or shared for cross-context behavioral advertising....
Why it matters: This provision establishes the categories of sensitive data T-Mobile collects and the consent conditions limiting their use for advertising purposes, explicitly anchoring the default use restrictions to CCPA regulatory section 7027(m) and defining the boundary between permissible operational use and consent-required advertising use....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states T-Mobile collects location data from all devices and home internet gateways on its network for service delivery, fraud detection, and emergency response purposes, and may use precise location for advertising with consent, while committing not to share or sell precise location for targeted advertising without consent....
Why it matters: This provision establishes that location data collection is continuous for all network-connected devices and home gateways, with an explicit consent requirement imposed before precise location is used for advertising or shared with advertising partners, creating a consent-gated boundary for advertising use of this sensitive data category....
-
Roblox
· Roblox Privacy Policy
The policy states that audio captured through a user's device during voice feature use is monitored, collected, stored, and used for voice chat, safety enforcement, AI model training, and product improvement. This provision applies to users 13 and older....
Why it matters: This provision establishes that audio data collected through voice features is retained and used for AI training and product improvement purposes in addition to the primary safety and communications functions, which may require evaluation under GDPR lawful basis requirements, state-level biometric and wiretapping consent laws, and emerging AI training data regulations depending on user jurisdiction....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Roblox
· Roblox Privacy Policy
The policy states that Roblox may collect facial images, including selfies, to estimate a user's age, and that such images are deleted after the age assurance process is completed. Additional detail is provided in a separate Roblox Facial Media Capture Policy....
Why it matters: This provision establishes a biometric data collection practice for age estimation purposes, which may require evaluation under state biometric privacy laws including Illinois BIPA, Texas CUBI, and Washington's My Health My Data Act, as well as GDPR's requirements for processing biometric data as a special category under Article 9....
-
Samsung
· Samsung Privacy Policy
The US Supplement states that Samsung may use personal information about US residents to develop and train its artificial intelligence algorithms and models, in addition to the purposes described in the main policy. The document does not specify which categories of personal information are eligible for AI training use or whether separate consent is required....
Why it matters: This provision appears only in the US Supplement rather than the main policy body, and the document does not limit the categories of personal information that may be applied to AI training. Compliance teams should evaluate whether this disclosure satisfies notice and secondary-use consent requirements under applicable state privacy laws, particularly in states that require explicit consent or opt-out mechanisms for secondary processing....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung shares identifiers and online activity data with advertising services via automated technologies and server-to-server connections, and acknowledges this may constitute a sale of personal information or use for targeted advertising under applicable state privacy laws. Users who have consented may have their personal information shared for personalized ad delivery....
Why it matters: This provision establishes that Samsung's ad data sharing practices may trigger sale or targeted advertising definitions under state privacy laws such as the CCPA and CPRA, requiring Samsung to honor opt-out requests submitted through the designated mechanisms. The use of server-to-server connections alongside automated technologies broadens the scope of third-party data access beyond cookie-based collection....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung's services may automatically generate biometric data including face-clustering data that groups images of the same face across photos stored on the device, and that this data remains on-device and is not accessed, transferred to, or shared by Samsung. Deletion of this data is the user's responsibility through device settings, factory reset, or photo deletion....
Why it matters: The automatic generation of face-clustering data from stored photos may implicate state biometric privacy laws such as the Illinois Biometric Information Privacy Act (BIPA), which imposes specific notice, consent, and retention requirements for biometric identifiers generated from facial geometry. The policy's assertion that Samsung does not access this data limits Samsung's ability to fulfill deletion requests on behalf of users....
-
Grammarly
· Grammarly Privacy Policy
The policy states that when users activate the Notetaker or transcription features, Superhuman collects audio recordings of communications, including recordings of non-user participants in those communications, to generate transcriptions....
Why it matters: This provision discloses that audio recordings of third parties who are not Superhuman users may be captured when a user activates transcription features, raising consent and notice obligations that may vary by jurisdiction....
-
HubSpot
· HubSpot Privacy Policy
The policy states that HubSpot collects professional personal data including business contact information from public sources, third-party providers, and its own customers, and distributes this data to other HubSpot customers for sales and marketing use through enrichment product features....
Why it matters: This provision establishes HubSpot's role as a controller of a commercial dataset of professional personal data that is collected from individuals who are not direct HubSpot users and made available to paying customers. The policy relies on legitimate interests as the legal basis for this processing, asserting that people would expect their work-related data to be shared in this way....
-
Asana
· Asana Privacy Statement
Asana AI features that rely on AI Partners process metadata, personal information, and user-generated content such as task titles and task descriptions, in contrast to Asana's own AI features which are limited to metadata only....
Why it matters: This provision distinguishes two categories of AI processing with materially different data scope: features powered by AI Partners access user-generated content and personal information, which may implicate subprocessor obligations, data minimization requirements, and consent mechanisms under GDPR and CCPA....
-
Asana
· Asana Privacy Statement
HIPAA-covered entities and business associates must execute a separate Business Associate Addendum with Asana to establish HIPAA-compliant use of the platform; the standard DPA alone does not provide HIPAA coverage....
Why it matters: This provision establishes that HIPAA compliance requires a separately executed BAA, which is an operationally distinct step from the DPA incorporation by reference, creating an affirmative obligation for healthcare-regulated customers to independently execute this agreement....
-
Klarna
· Klarna Privacy Policy
The document authorizes Klarna to share personal data with cloud computing platforms, payment service providers, advertising and marketing partners, and regulatory authorities, for purposes including fraud prevention, credit risk assessment, and marketing and advertising....
Why it matters: This provision authorizes sharing of personal data, which may include financial and behavioral data, with advertising and marketing partners, a category that engages GLBA NPI sharing opt-out requirements and CCPA sale or sharing disclosure obligations given the nature of the data Klarna processes....
-
Mercury
· Mercury Privacy Policy
The policy authorizes collection of voiceprints, facial scans, and biometrics extracted from photographs for identity verification and related purposes, and classifies this data as Sensitive Personal Information under California law....
Why it matters: This provision authorizes collection of biometric identifiers that are subject to distinct statutory frameworks in several U.S. states, including Illinois BIPA, Texas CUBI, and Washington state law, which impose written consent, retention schedule, and data destruction requirements beyond what this policy's general language specifies....
-
Synthesia
· Synthesia Privacy Policy
The policy discloses that creating an avatar on Synthesia requires processing biometric data including facial geometry and voiceprints, classified as special category data under GDPR and as biometric identifiers under the Illinois Biometric Information Privacy Act. Processing occurs for avatar generation, identity verification, fraud prevention, and AI model fine-tuning....
Why it matters: This provision establishes that avatar creation constitutes biometric data processing subject to heightened legal obligations under GDPR Article 9 and the Illinois Biometric Information Privacy Act, requiring explicit consent as a derogation and compliance with jurisdiction-specific retention, disclosure, and prohibition-on-sale requirements. Enterprise customers deploying Synthesia for employee avatar creation should assess their own obligations as data controllers under these frameworks....
-
Ideogram
· Ideogram Terms of Service
The agreement requires disputes to be resolved through binding individual arbitration rather than court proceedings, and waives the right to participate in class, consolidated, or representative actions; a carve-out permits either party to seek injunctive relief in court for intellectual property disputes....
Why it matters: This provision requires disputes to proceed through binding individual arbitration and bars participation in class or representative actions. The agreement does not specify an arbitration administrator, arbitration rules, or the seat of arbitration, which creates procedural ambiguity regarding how arbitration would be conducted in practice....
-
Comcast
· Comcast Terms of Service
The agreement requires that all disputes between subscribers and Comcast be resolved through individual arbitration or small claims court, with an opt-out procedure available within a specified timeframe. Arbitration proceedings involve less discovery and fewer appellate options than court litigation....
Why it matters: This provision establishes the exclusive dispute resolution mechanism for all claims arising under the agreement across all covered Xfinity services, channeling disputes away from court proceedings and into individual arbitration....
-
Comcast
· Comcast Terms of Service
The agreement includes a separate waiver of jury trial rights and a waiver of class, collective, and representative action rights, with the class action waiver applying to the extent permitted by applicable state law....
Why it matters: This provision establishes dual procedural limitations: a jury trial waiver and a class action waiver that operate separately from the arbitration provision and apply to the extent permitted under each subscriber's state law....
-
Comcast
· Comcast Terms of Service
The agreement authorizes Comcast to change service features, pricing, and rates at any time, with or without advance notice, subject to applicable law. Continued use of services for more than 30 days after a change constitutes subscriber acceptance of that change....
Why it matters: This provision establishes a unilateral modification mechanism under which pricing and service terms may change at any time, with continued service use functioning as the operative consent mechanism, and cancellation as the alternative available to subscribers who object to a material negative change....
-
Tabnine
· Tabnine Privacy Policy
When users access Tabnine through an employer or organizational account, the organization is designated as Data Controller and bears sole responsibility for providing required privacy notices, obtaining necessary consents, and complying with applicable data protection law with respect to its users' personal data. Tabnine operates as Data Processor in this configuration....
Why it matters: This provision places the full burden of user notice, consent, and data protection compliance on enterprise business partners rather than on Tabnine, which is a material allocation of regulatory risk that must be reflected in data processing agreements between organizations and Tabnine. Enterprise customers that fail to satisfy these obligations may face direct regulatory exposure under GDPR and CCPA as Data Controllers....
-
Inflection AI
· Inflection AI Privacy Policy
Users retain ownership of their inputs and AI-generated outputs, but grant Inflection AI a royalty-free, perpetual, irrevocable, sublicensable worldwide license over that content for service operation and model improvement purposes. The license is described as limited to specified purposes but is perpetual and irrevocable in duration and scope....
Why it matters: This provision establishes a content license that is perpetual and irrevocable in its stated terms, meaning the license persists even after account deletion or service discontinuation. The sublicensable nature of the license through multiple tiers means Inflection AI may authorize third-party service providers to use the licensed content under this grant....
-
Inflection AI
· Inflection AI Privacy Policy
The Terms of Service require most disputes between users and Inflection AI to be resolved through individual arbitration rather than class actions, representative proceedings, or jury trials. Users have the option to opt out of arbitration within 30 days by following the procedure described in Section 13.10....
Why it matters: This provision establishes individual arbitration as the default dispute resolution mechanism and waives class action rights for users who do not opt out within the stated window. The 30-day opt-out period requires affirmative action by users who wish to preserve access to court-based dispute resolution....
-
Inflection AI
· Inflection AI Privacy Policy
The policy states that Inflection AI may derive inferences about a user's emotional state, tone, and sentiments from their inputs. An opt-out specifically for voice-based emotional inference is available in account settings....
Why it matters: This provision discloses the derivation of emotional and psychological characteristics from user inputs, which may constitute processing of special categories of inferred data under GDPR or sensitive personal information under certain U.S. state privacy laws. The opt-out is limited to voice-based emotional inference, which does not necessarily extend to text-based sentiment inference....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement requires that most disputes between users and Hims & Hers, Medical Groups, or Providers be resolved through binding individual arbitration rather than court proceedings, and both parties waive the right to a jury trial and class action participation. A 30-day opt-out window is available from the date of first acceptance....
Why it matters: This provision requires disputes to proceed through individual binding arbitration rather than civil litigation or class action, covering not only Hims & Hers but also Medical Groups and Providers as named beneficiaries of the clause. The scope of the waiver and its extension to third-party medical entities may require evaluation under applicable state law, as certain jurisdictions limit the enforceability of consumer arbitration waivers in healthcare contexts....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement asserts that Hims & Hers as the direct platform operator is not a HIPAA covered entity, and acknowledges that affiliated Labs, Pharmacies, and Medical Groups may or may not be covered entities or business associates under HIPAA. This means health information provided to Hims & Hers directly may not receive HIPAA protections as applied to the platform operator....
Why it matters: This provision establishes that health and medical information processed by Hims & Hers as the platform operator is not subject to HIPAA protections as applied directly to that entity, while acknowledging uncertainty about the HIPAA status of affiliated clinical partners. Legal and compliance teams should evaluate whether applicable state health data privacy laws and FTC health breach notification rules provide alternative protections for health data processed outside the HIPAA framework....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement establishes that use of the platform constitutes a request by the user for Hims & Hers and Medical Groups to process sensitive personal information, including health information, as necessary to provide the service, including personalized recommendations delivered by email and on the platform....
Why it matters: This provision frames the processing of sensitive personal information, including health and mental health data, as user-initiated through the act of using the service, which structures consent as implicit in platform use rather than through a separate affirmative consent mechanism. The consent-through-use framing may require evaluation against state privacy laws that impose specific opt-in consent requirements for sensitive data processing....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy explicitly states that Hims & Hers may sell sensitive personal data, including health data and sexual orientation information, as those terms are defined under California and other state privacy laws, through disclosures to advertising and analytics partners....
Why it matters: This provision establishes that data disclosures to third-party advertising and analytics partners may constitute a sale of sensitive personal information under applicable state law definitions, triggering opt-out rights and, in some jurisdictions, opt-in consent requirements for sensitive data categories....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy authorizes sharing of sensitive personal information including health data and sexual orientation or sex life information with advertising partners to enable personalized advertising and lookalike audience targeting, provided that information does not qualify as Protected Information under HIPAA or applicable state health law....
Why it matters: This provision establishes that health-related browsing activity on the Hims & Hers platform, including pages viewed about specific medical conditions or treatments, may be disclosed to external advertising partners for cross-site ad targeting, subject to the company's determination of whether that data constitutes Protected Information....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states that Hims & Hers is not a HIPAA covered entity, acknowledges it may in some cases function as a HIPAA business associate, and notes that HIPAA protections may not apply to user transactions depending on the specific service and entity involved....
Why it matters: This provision establishes that the full range of HIPAA protections does not apply to all user interactions with the Hims & Hers platform, and that the applicability of HIPAA depends on the specific transactional context, creating a variable protection landscape across the company's telehealth, pharmacy, and consumer wellness services....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states that the company or its service providers may collect and use biometric information for the purpose of identity verification prior to service access....
Why it matters: This provision authorizes collection of biometric information, a category subject to distinct state biometric privacy statutes including the Illinois Biometric Information Privacy Act, which impose specific consent, retention, and destruction obligations that may apply depending on user location....
-
Replit
· Replit Privacy Policy
The policy places responsibility on developers who publish content on Replit that collects personal information from users to comply with all applicable privacy laws, including COPPA notice and verifiable parental consent requirements, independently of Replit....
Why it matters: This provision establishes that developers publishing data-collecting content on the Replit platform bear direct legal responsibility for COPPA compliance, parental consent acquisition, and user rights obligations. Compliance teams at organizations deploying Replit-based applications that interact with minors or collect user data should assess this delegation of compliance responsibility....
-
Poshmark
· Poshmark Privacy Policy
The terms require that most disputes between users and Poshmark be resolved through binding individual arbitration rather than court proceedings, and prohibit class arbitration, class actions, and representative proceedings. A 60-day informal resolution process is a condition precedent to initiating arbitration....
Why it matters: This provision requires disputes to proceed through individual arbitration, which is a separate procedural pathway from court litigation. The clause prohibits class actions, meaning users must resolve claims individually. A 60-day informal resolution period, including a mandatory video conference if requested, is established as a condition that must be satisfied before arbitration may be initiated....
-
Google Gemini
· Gemini Apps Privacy Notice
A subset of user chats, along with associated language, device type, location, and feedback data, are reviewed by human reviewers including trained third-party service providers, and retained for up to three years regardless of whether the user deletes their Gemini Apps activity. Reviewed chats are disconnected from the user's Google account before being sent to service providers....
Why it matters: This provision establishes a retention mechanism for human-reviewed chat data that operates independently of the user's deletion controls in Gemini Apps Activity, meaning user-initiated deletion of activity does not trigger deletion of this data subset. Compliance teams should assess whether this retention architecture satisfies GDPR and UK GDPR erasure request obligations, particularly given that the three-year retention period applies to data that includes location information, device type, and feedback alongside chat content....
-
Google Gemini
· Gemini Apps Privacy Notice
When the Keep Activity setting is on, Google uses saved chats, uploaded files, videos, screens, photos, audio, Gemini Live recordings, feedback, website visit information, and location data to train generative AI models. Turning off Keep Activity prevents future chats from being used for AI model training unless the user submits feedback....
Why it matters: This provision establishes that a broad range of data categories, including screen content, audio recordings, and uploaded files, are used for generative AI model training when Keep Activity is enabled, and that the default auto-delete period is 18 months. The notice discloses that even with Keep Activity off, feedback submissions trigger collection and use of the preceding 24 hours of chat context for model improvement purposes....
-
Google Gemini
· Gemini Apps Privacy Notice
Google explicitly states it does not monitor or secure data from custom third-party Connected Apps, including Model Context Protocol server tools, and advises that connecting such apps may expose user data, passwords, devices, and accounts to unauthorized access. Data shared by Gemini with third-party Connected Apps is governed solely by those apps' own privacy policies, and deletion of Gemini Apps activity does not trigger deletion of data those apps have already received....
Why it matters: This provision explicitly disclaims Google's responsibility for monitoring or securing data flows to custom third-party Connected Apps, and discloses a specific risk of unauthorized access to user data, passwords, devices, and accounts. Compliance teams should note that this creates a data flow architecture where personal data processed by Gemini, potentially including sensitive categories, may be transmitted to third-party services outside Google's data governance framework without user deletion rights propagating to those services....
-
Google Gemini
· Gemini Apps Privacy Notice
Gemini mobile apps collect system permissions and device data including call and message logs, contacts, installed apps, language preferences, screen content, app context and URLs, and remote browser data including cookies containing website authentication information and screen captures. This data is collected to enable Gemini mobile app functionality....
Why it matters: This provision establishes that Gemini mobile apps access a broad range of on-device data categories, including call and message logs, contacts, screen content, and remote browser cookies containing authentication credentials. The collection of authentication-bearing cookies as part of remote browser functionality is an operationally distinct disclosure that compliance teams and security professionals should note....
-
Google Gemini
· Gemini Apps Privacy Notice
Google asserts legitimate interests as the legal basis under GDPR and UK GDPR for processing user Gemini Apps data, including prompts, uploaded content, audio, video, and Connected Apps data, to train generative AI models and develop new machine learning technologies. This basis is applied to data from both publicly accessible sources and user-provided Gemini Apps information....
Why it matters: This provision asserts legitimate interests as the legal basis for AI model training using a broad range of user data categories under EU and UK data protection law, which requires Google to demonstrate that this processing meets the GDPR balancing test. Compliance teams in the EU and UK should note that the breadth of data categories and the commercial nature of AI model development may be subject to regulatory scrutiny regarding whether legitimate interests genuinely outweigh data subject interests in this context....
-
Twilio
· Twilio Privacy Notice
The notice discloses that for the Conversational Intelligence service, which transcribes and analyzes voice calls using AI and ML, Twilio processes personal data within voice calls as an independent controller rather than as a data processor acting on customer instructions....
Why it matters: This provision establishes that Twilio assumes independent data controller status for voice call transcription and analysis under the Conversational Intelligence service, which means Twilio determines the purposes and means of processing personal data contained in voice calls rather than acting under customer direction. This structural classification has direct implications for data subject rights allocation and DPA terms between Twilio and its enterprise customers....
-
Poshmark
· Poshmark Terms of Service
By posting any content on Poshmark, users grant the company a permanent, irrevocable, royalty-free right to copy, modify, distribute, and use that content for any purpose including advertising and marketing across any platform or medium, including third-party social networks....
Why it matters: This provision establishes a license that does not terminate when a user deletes content or closes an account, as it is characterized as perpetual and irrevocable. The license expressly covers promotional and advertising use across third-party platforms, meaning user-submitted listing photos and descriptions may be used in Poshmark marketing campaigns beyond the marketplace itself....
-
Poshmark
· Poshmark Terms of Service
The agreement requires disputes between users and Poshmark to be resolved through individual binding arbitration rather than court proceedings, and waives the right to participate in class arbitrations, class actions, or any representative proceeding....
Why it matters: This provision requires disputes to proceed through individual binding arbitration following a mandatory 60-day informal resolution period, and prohibits class or representative proceedings. The Federal Arbitration Act is cited as the governing framework, and the clause applies to all claims including those based in contract, tort, statute, fraud, or misrepresentation....
-
Poshmark
· Poshmark Terms of Service
Poshmark's total financial liability for any claim is capped at the greater of fees the user paid as a seller in the prior six months or USD $100, with exceptions for gross negligence, fraud, or intentional misconduct, and for liability that cannot be excluded by law....
Why it matters: This provision establishes a financial ceiling on all recoverable damages from Poshmark regardless of claim type or the amount of a transaction in dispute. For buyers who have not paid seller fees, the cap defaults to USD $100, which may be substantially less than the value of a disputed transaction....
-
Google Maps
· Google Maps Platform Terms of Service
The agreement prohibits customers from using any Google Maps Content to train, test, validate, or fine-tune machine learning or artificial intelligence models, as one of several enumerated prohibitions on creating content from Google Maps Content....
Why it matters: This provision establishes a license condition that directly restricts how customers may use geospatial data obtained through the Maps Platform, including in downstream AI and ML development workflows. A breach of this restriction is identified in Section 5.2(d) as a basis for immediate service suspension without the 24-hour cure period available for AUP violations....
-
Google Maps
· Google Maps Platform Terms of Service
The agreement requires that customer applications notify end users in advance of data collection types and any combination of location data with other providers' data, and prohibits obtaining or caching end user location data without express, prior, and revocable consent....
Why it matters: This provision establishes specific consent and disclosure standards for location data that customers must implement in their applications, including a revocability requirement that interacts with GDPR consent standards and CCPA opt-out rights. Failure to comply with this provision is identified in Section 5.2(d) as a basis for immediate service suspension....
-
Google Maps
· Google Maps Platform Terms of Service
The agreement authorizes Google to immediately suspend a customer's access to the Services without a prior notice or cure period if Google reasonably believes suspension is needed to protect its infrastructure, if required by law, if unauthorized access is suspected, or if the customer violates the license restrictions or data protection provisions....
Why it matters: This provision establishes conditions under which Google may suspend service access immediately and without the 24-hour cure period available under Section 5.1 for AUP violations, including for license restriction violations such as the AI training prohibition and data protection violations. Customers with Maps-dependent applications face operational continuity risk if suspension occurs without advance notice....
-
Google Maps
· Google Maps Platform Terms of Service
The agreement prohibits customers from using the Services in applications that qualify as websites or online services directed to children under COPPA, and from using the Services for High Risk Activities as defined in the agreement....
Why it matters: This provision establishes a license restriction that prohibits COPPA-covered applications from integrating Google Maps Platform services, which may affect edtech platforms, children's entertainment services, and other applications that may qualify as directed to children under the FTC's COPPA Rule. Non-compliance constitutes a license breach that can trigger immediate suspension....
-
Intuit
· Intuit Privacy Statement
Intuit combines personal information across its distinct products, including QuickBooks, Mailchimp, TurboTax, and Credit Karma, to deliver unified experiences across the Intuit Platform, rather than treating each product's data in isolation. TurboTax data is used with consent where required, but other product data may be combined without separate per-product consent....
Why it matters: This provision establishes a cross-product data aggregation architecture that links financial, tax, bookkeeping, marketing, and credit data under a single platform framework. Compliance teams should evaluate whether the consent basis for aggregated use satisfies GDPR purpose limitation and data minimization requirements, particularly for EU and UK users, and whether CCPA service provider or contractor restrictions apply to intra-group data flows....
-
Intuit
· Intuit Privacy Statement
Intuit states it uses personal information, including financial, tax, and behavioral data, to train its AI and machine learning models, with a specific carve-out excluding Google Workspace API data from generalized AI or ML model training....
Why it matters: This provision establishes that personal information processed across Intuit's platform, including financial transactions, tax return data, and behavioral interactions, may be used as training data for Intuit's AI systems and shared with generative AI providers designated as service providers. Legal teams should assess whether this use falls within the lawful basis asserted at the time of collection and whether adequate disclosures and controls exist for EU, UK, and California users....
-
Intuit
· Intuit Privacy Statement
Intuit deploys session-replay technologies from FullStory and Medallia that record user interactions including clicks, keystrokes, mouse movements, and scrolls during sessions on Intuit's services. Users can opt out of FullStory recording at a provided URL; a comparable Medallia opt-out link is not specified in the document text provided....
Why it matters: This provision discloses the deployment of third-party session-replay tools that capture keystroke-level user interaction data on financial and tax preparation platforms, where users routinely enter sensitive personal and financial information. Legal teams should evaluate this practice under state electronic communications interception statutes, including California's CIPA and similar laws in other states, as well as GDPR transparency and consent requirements for EU users....
-
Intuit
· Intuit Privacy Statement
Intuit states it collects biometric personal information through certain parts of its platform, and the policy requires that notice be provided and consent obtained before collection, with detailed practices disclosed in a separate Biometric Notice....
Why it matters: This provision discloses biometric information collection across parts of the Intuit Platform, subject to a notice-and-consent requirement and a separate Biometric Notice. Legal teams should assess compliance with Illinois BIPA, Texas CUBI, Washington's biometric law, and other state biometric statutes, which impose specific retention schedules, destruction requirements, and written release requirements beyond general consent....