-
Waze
· Waze Privacy Policy
The policy states that Waze collects data about user activity on third-party sites and apps that are linked to a Waze account or accessed through the Waze service....
Why it matters: This provision establishes that data collection extends beyond Waze's own platform to include activity on third-party services accessed through or linked to Waze, the scope of which depends on which third-party integrations a user activates....
-
Waze
· Waze Privacy Policy
The policy states that users in the EU, UK, Israel, and Brazil have rights to access, update, correct, delete, restrict, and export their data, and to object to processing, with requests submitted to privacy@waze.com....
Why it matters: This provision establishes the operational mechanism for exercising data subject rights under GDPR, UK GDPR, Israeli data protection law, and LGPD, including the contact point and the data export process available through the Waze website dashboard....
-
Uniswap
· Uniswap Terms of Service
The agreement reserves Uniswap Labs' right to revoke user-claimed subdomains and usernames at its discretion and without notice, including for terms violations, unlawful behavior, conduct that harms the service, offensive names, or to comply with legal requirements....
Why it matters: This provision establishes that username access can be revoked without notice at Uniswap Labs' discretion, including for subjective criteria such as names deemed offensive; users whose wallet identity and public profile are associated with a subdomain should be aware that this association can be administratively terminated without prior notification....
-
BeReal
· BeReal Terms of Service
BeReal reserves the right to permanently delete accounts after two years of continuous inactivity for European and non-US users, or after three years for US-based users, calculated from the date of last login. BeReal may send an SMS notification prior to deletion, giving users the opportunity to log in and retain their account....
Why it matters: This provision establishes region-differentiated inactivity deletion thresholds, with a shorter period for European users that the document attributes to legal data protection obligations, consistent with GDPR data minimization and storage limitation principles. Deletion is stated to be permanent, and the prior notification is described as an SMS that BeReal may (not must) send....
-
BeReal
· BeReal Terms of Service
The agreement limits BeReal's liability, including that of its affiliates, officers, directors, employees, agents, and licensors, to the maximum extent permitted by the applicable law of the user's country of residence....
Why it matters: This provision asserts a broad liability cap covering BeReal and an extensive list of associated entities, subject to the limits of applicable local law. The provision does not specify a monetary cap or enumerate excluded categories of harm, instead delegating the effective limit to local law, which produces jurisdiction-dependent outcomes....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
BeReal
· BeReal Terms of Service
BeReal reserves the right to update the user agreement at any time, with advance notice required only for changes that affect rights or obligations (except for security or compliance-driven updates). Continued use of the service after the effective date constitutes acceptance of the updated terms....
Why it matters: This provision establishes continued use as the mechanism for accepting updated terms, with the notification obligation conditioned on the materiality of the change and subject to security and compliance exceptions. The 'reasonable time' notification standard is not defined in the document....
-
ADP
· ADP Privacy Statement
The policy establishes procedures for individuals to request access to, correction of, or deletion of their personal data, and to object to processing, either through their online account or by contacting privacy@adp.com. For EEA individuals, additional rights including data portability and rights regarding automated decision-making are also stated....
Why it matters: This provision establishes the operational mechanism through which individuals may exercise data rights under GDPR, UK GDPR, CCPA, and the ADP BCR framework. EEA individuals have an additional right of data portability and notification regarding automated decision-making, with a dedicated EMEA Data Protection Officer contact provided....
-
ADP
· ADP Privacy Statement
The policy states that personal data is retained only as long as necessary for stated business purposes, legal compliance, or applicable statutes of limitations, following ADP's Global Records Information Management Policy, and is securely deleted, destroyed, de-identified, or archived at the end of the retention period....
Why it matters: The retention framework references ADP's internal Global RIM Policy and records retention schedules as the governing mechanism, but those schedules are not published or disclosed in this document. The stated disposal methods include archiving as an alternative to deletion, which may affect the practical exercise of erasure rights....
-
Grindr
· Grindr Privacy Policy
The policy states that Grindr may revise the policy at any time and that advance notice of changes will be provided only when Grindr determines, in its sole discretion, that the changes are material; the current policy version governs data processing at all times....
Why it matters: This provision reserves to Grindr the unilateral determination of whether policy changes are material and therefore subject to advance notice; changes Grindr does not classify as material may be implemented without prior notification to users, with the current posted policy governing data processing....
-
BeReal
· BeReal Privacy Policy
The policy states that BeReal records touch and swipe interactions with the app interface for a randomized 0.001% sample of users, conducted via an analytics partner, retained for a maximum of 90 days, and not deployed in all geographic regions....
Why it matters: This provision establishes a session recording program involving a third-party analytics partner. The geographic deployment limitation and the involvement of an external partner in processing interaction recordings may require evaluation under applicable regional data protection law and subprocessor disclosure requirements....
-
BeReal
· BeReal Privacy Policy
The policy states that accounts inactive for three years (U.S. users) or two years (EU and other users) may be permanently deleted along with associated data, with inactivity defined strictly as absence of login or connection, and that BeReal may send an SMS notice before deletion....
Why it matters: This provision establishes differentiated inactivity-based deletion timelines by jurisdiction and defines inactivity narrowly as login or connection events. The notice mechanism is framed as permissive ('may send') rather than mandatory, which means users cannot rely on receiving advance notice before deletion occurs....
-
BeReal
· BeReal Privacy Policy
The policy states that all users globally are granted rights to access, rectify, erase, restrict, object to, and port their personal data, as well as to withdraw consent, with some rights (rectification, deletion, consent withdrawal) exercisable directly in the app and all rights exercisable by contacting dpo@bere.al. French users are additionally granted a post-mortem data instruction right....
Why it matters: This provision establishes that BeReal extends GDPR-equivalent data subject rights to all users globally, not only those in jurisdictions where such rights are legally mandated. The policy identifies dpo@bere.al as the contact for rights requests and states a 45-day response window for access, deletion, correction, and portability requests under U.S. law, with California opt-out requests processed within 15 business days....
-
Betterment
· Betterment Privacy Policy
The policy states that Betterment retains all customer data for a minimum of three years due to U.S. regulatory requirements, and continues to retain data on closed or deleted accounts for legal, regulatory, and security purposes....
Why it matters: This provision establishes that deletion requests, including account closure requests, do not result in full data removal; data is retained for at minimum three years under stated regulatory obligations, and potentially longer for legal or security purposes....
-
Betterment
· Betterment Privacy Policy
The policy states that customers acknowledge and agree that Betterment will compare their identifying information against government-provided lists of suspected terrorists as part of its compliance procedures....
Why it matters: This provision discloses that customer identity data is screened against government terrorism watchlists, a practice required under federal Bank Secrecy Act and USA PATRIOT Act obligations for financial institutions, and reflects a mandatory compliance obligation rather than a discretionary data use....
-
Betterment
· Betterment Privacy Policy
The policy states that residents of qualifying U.S. states, including California, have rights to access, delete, and correct their personal data, to opt out of sales or sharing of personal data, and to limit use of sensitive personal information, subject to GLBA exceptions; requests are processed via email to privacy@betterment.com, with data access and portability requests limited to twice per 12-month period....
Why it matters: This provision establishes the mechanism and frequency limits for consumer data rights requests under state privacy laws, and conditions the exercise of those rights on GLBA exemptions that may reduce the scope of available remedies for financial data categories....
-
Google Ads
· Google Ads Editorial and Technical Requirements
The policy states that editorial policy violations will not result in immediate account suspension; a warning must be issued at least 7 days before any suspension action is taken....
Why it matters: This provision establishes a minimum procedural timeline between violation notice and suspension enforcement, giving advertisers a defined window to remediate disapprovals before losing account access. Compliance teams should incorporate this 7-day threshold into escalation and remediation workflows....
-
Google Ads
· Google Ads Editorial and Technical Requirements
The policy prohibits images that are improperly oriented, do not fill the designated image space, are blurry or illegible, contain strobing or flashing effects, or expand beyond the ad frame into surrounding website or app content....
Why it matters: This provision establishes specific technical and visual quality thresholds that image-based ad creatives must meet for approval. Ads using animated, low-resolution, or improperly sized images will be disapproved, affecting campaign delivery....
-
Google Ads
· Google Ads Editorial and Technical Requirements
The policy prohibits advertisers from including phone numbers directly within ad text fields, requiring instead that phone numbers be used through designated ad features such as call assets....
Why it matters: This provision requires advertisers to route phone number display through Google's designated call tracking and asset features rather than embedding numbers in free-text ad copy, which affects how advertiser-to-consumer phone contact is facilitated through the platform....
-
Google Ads
· Google Ads Editorial and Technical Requirements
The policy prohibits non-standard or gimmicky repetition of names, words, or phrases in ads, and also prohibits asset text that duplicates words or phrases within the same asset or across other assets in the same ad group, campaign, or account....
Why it matters: This provision extends the repetition prohibition beyond individual ad creatives to encompass asset-level text duplication across ad groups, campaigns, and accounts, creating a cross-campaign content review obligation for advertisers managing large or multi-campaign account structures....
-
Google Ads
· Google Ads Editorial and Technical Requirements
The policy requires ads to use commonly accepted spelling and grammar, be comprehensible, stay within character limits for double-width character languages, and conform to the informational presentation style of Google Search results....
Why it matters: This provision applies specific character limit requirements to double-width character languages, creating a language-specific technical compliance obligation relevant to advertisers running campaigns in Chinese, Japanese, Korean, and similar scripts. The requirement to conform to the 'clear and informational presentation style of the Google Search results' sets an open-ended stylistic standard subject to Google's own determination....
-
Google Ads
· Google Ads Prohibited Content Policy
Google states that the English version of its advertising policies is the authoritative enforcement basis, and that translated versions are not intended to modify policy content. Policy enforcement decisions are based on the English-language text regardless of the language version an advertiser may have consulted....
Why it matters: This provision establishes that non-English-speaking advertisers who consult translated versions of the policy are subject to enforcement based on English-language text that may differ from the translation they relied upon, which may create compliance exposure where translation discrepancies exist....
-
DocuSign
· DocuSign Privacy Statement
The notice states that DocuSign does not knowingly sell personal information of minors under 16 without legally required affirmative authorization, and that the company recognizes browser-based opt-out preference signals in accordance with applicable law....
Why it matters: This provision addresses CCPA-specific obligations regarding minor data and browser-based opt-out signals, including Global Privacy Control recognition. The statement that DocuSign's services are not designed for or marketed to minors under 18 is separately established in the Children's Privacy section....
-
Medium
· Medium Privacy Policy
The policy states that when users interact with embedded third-party content on Medium pages, the hosting third party may collect data including IP address and interaction data directly, and that Medium's privacy policy does not govern this collection....
Why it matters: This provision establishes that Medium's privacy protections and data rights mechanisms do not apply to data collected by third-party embed providers, and that Medium does not control or take responsibility for that collection. Users interacting with embedded video, audio, or other content are subject to the embed provider's own privacy terms....
-
Medium
· Medium Privacy Policy
The policy states that account data is deleted within 14 days of account closure, but that certain information may be retained beyond this period as required by law or for legitimate business purposes, without specifying which data categories or retention durations apply....
Why it matters: This provision establishes a 14-day account data deletion timeline upon account closure but includes a carve-out for retention required by law or legitimate business purposes, the scope of which is not defined in the document....
-
Medium
· Medium Privacy Policy
The policy states that users who opt into the address book feature have their contact names and email addresses converted to encrypted non-reversible identifiers, matched against Medium's member database, with non-member identifiers deleted immediately and all identifiers deleted within 30 days....
Why it matters: This provision describes a contact matching process that processes personal data of individuals who are not Medium users, relying on legitimate interests as the stated lawful basis. The policy states that non-member identifiers are deleted immediately after matching, and all identifiers within 30 days, which are concrete operational data minimization commitments....
-
Medium
· Medium Privacy Policy
The policy states that changes may be made at any time, with notification provided by updating the effective date at minimum, and additional notice at Medium's discretion in some cases....
Why it matters: This provision establishes that the effective date revision is the minimum required notification for policy changes, with more prominent notice provided only at Medium's discretion. Users who do not actively monitor the policy may not receive proactive notification of material changes....
-
Zillow
· Zillow Privacy Notice
The policy states that all categories of personal data Zillow collects may be disclosed to third parties during negotiation of or in connection with a corporate merger, acquisition, joint venture, asset sale, or financing transaction, and also in insolvency, bankruptcy, or receivership proceedings....
Why it matters: This provision establishes that the full scope of Zillow-collected personal data may be transferred to acquiring or counterparty entities as part of a corporate transaction, including during the negotiation phase before any transaction is completed. This is a standard commercial provision but is operationally significant given the breadth of data categories Zillow collects, including home search histories, contact information, and geolocation data....
-
Zillow
· Zillow Privacy Notice
The policy states Zillow's services are not directed to children under 13, that Zillow does not knowingly collect personal data from children under 13, and that upon learning such data was collected, Zillow will promptly delete it. Parents or guardians may contact Zillow to request deletion of a child's data....
Why it matters: This provision establishes Zillow's stated compliance posture under the Children's Online Privacy Protection Act (COPPA), which prohibits operators of general audience websites from knowingly collecting personal data from children under 13 without verifiable parental consent. The deletion commitment upon discovery is consistent with standard COPPA compliance practice....
-
Zillow
· Zillow Privacy Notice
The policy states Zillow retains personal data for as long as reasonably necessary for the purposes collected, accounting for account duration, legal and tax obligations, dispute resolution, litigation holds, and regulatory investigations. Upon expiration of the retention need, Zillow states it will delete or de-identify personal data, with the qualification that backup archive copies may be retained....
Why it matters: This provision establishes Zillow's stated retention framework but does not specify defined retention periods for any data category, leaving the operative timeframes dependent on the factors listed. The backup archive carve-out means personal data may persist beyond the primary retention period in backup systems until deletion or de-identification is operationally feasible....
-
Zillow
· Zillow Privacy Notice
The policy explicitly excludes ShowingTime+, Aryeo, Zillow Home Loans, and Spruce from the scope of this notice, stating that each of these entities has its own separate privacy notice governing the personal data they hold. Users interacting with those entities must consult the respective entity's privacy notice....
Why it matters: This provision establishes that the privacy protections, data sharing practices, and user rights described in this notice do not apply to Zillow Home Loans, ShowingTime+, Aryeo, or Spruce, which are Zillow Group affiliates. Users who interact with multiple Zillow Group brands may be subject to materially different data practices depending on which entity's services they use, and must review each entity's notice separately....
-
Zillow
· Zillow Privacy Notice
The policy states that when a user consents to receive promotional calls or text messages, Zillow collects the user's IP address and a timestamp of consent as proof of that consent. This consent data is stated to be shared with third parties only for the purpose of proving that consent was given....
Why it matters: This provision establishes that Zillow generates and retains a consent audit trail including IP address and timestamp when users opt into promotional communications. The policy's restriction on sharing this data solely for proof-of-consent purposes is relevant to compliance with TCPA documentation requirements for promotional text messaging....
-
Ancestry
· Ancestry Privacy Statement
The agreement states that users may designate a Legacy Contact in Account Settings who, upon verification of a qualifying event such as death, will receive full account access and assume ownership of the account including all Personal Information contained within it....
Why it matters: This provision establishes a mechanism for transferring full account ownership including DNA Data and Genetic Information to a third party upon the account holder's death or incapacitation, which creates considerations for posthumous data rights, estate planning, and the scope of consent applicable to transferred genetic data under GDPR and state privacy frameworks....
-
WhatsApp
· WhatsApp Privacy Policy
The policy states that messages that cannot be immediately delivered to recipients are stored in encrypted form on WhatsApp servers for up to 30 days pending delivery, after which undelivered messages are deleted from servers....
Why it matters: This provision establishes that message content is retained on WhatsApp servers for up to 30 days in circumstances where delivery is not immediate, creating a defined window during which server-side message content could potentially be subject to legal process or government requests as described elsewhere in the policy....
-
WhatsApp
· WhatsApp Privacy Policy
The policy states that in the event of a merger, acquisition, restructuring, bankruptcy, or asset sale, WhatsApp will transfer user information to successor entities or new owners, subject to applicable data protection laws....
Why it matters: This provision establishes that user data constitutes a transferable asset in corporate transactions, and that successor entities or new owners will receive user information. The qualifier 'in accordance with applicable data protection laws' does not specify what notice or consent mechanisms would be provided to users in advance of such a transfer....
-
WhatsApp
· WhatsApp Privacy Policy
The policy states that users may delete their WhatsApp account at any time using the in-app feature, which results in deletion of account info, profile photo, undelivered messages, and message history from WhatsApp servers. The policy notes that removing the app from a device without using the in-app deletion feature does not trigger server-side data deletion....
Why it matters: This provision establishes the account deletion mechanism and specifies what data is deleted upon account closure. It also discloses that simply uninstalling the app does not delete server-side data, which is an operationally significant distinction for users who believe uninstallation is equivalent to account closure....
-
OpenSea
· OpenSea Privacy Policy
The policy asserts that OpenSea does not sell or share personal information as defined by the CCPA, including for residents under 16 years of age, and that this has been the practice for the preceding 12 months....
Why it matters: This provision makes an explicit CCPA-compliant no-sale declaration, which is an operationally significant disclosure for California residents and compliance teams assessing data monetization practices. The policy identifies six categories of personal information collected and shared with third parties over the prior 12 months, which compliance teams should evaluate against the CCPA's definition of sharing....
-
OpenSea
· OpenSea Privacy Policy
The policy states that OpenSea does not respond to browser Do Not Track signals on the basis that there is no common technical standard for their meaning....
Why it matters: This provision discloses that Do Not Track signals are not honored, which is relevant for users relying on browser-level privacy controls. Some U.S. state privacy laws, including the California Online Privacy Protection Act, require disclosure of whether a service responds to Do Not Track signals, and this statement satisfies that disclosure requirement....
-
Writer
· Writer Trust Center
The document states that Writer holds SOC 2 Type II, HIPAA Type 1, PCI compliance, and ISO/IEC 27001, 27701, and 42001 certifications, with annual SOC 2 examinations covering Security, Availability, and Confidentiality trust service criteria....
Why it matters: This provision discloses the third-party audit and certification framework Writer has implemented, which is a standard vendor due diligence reference point for enterprise procurement. The document states that SOC 2 Type II reports are available upon request to trust@writer.com, providing a defined access mechanism for audit evidence....
-
Writer
· Writer Trust Center
The document states that submission of the newsletter subscription form constitutes consent for Writer to contact the subscriber by email or phone with product updates, educational resources, and promotional information....
Why it matters: This provision establishes consent to marketing communications through form submission, which engages CAN-SPAM requirements for email, TCPA requirements for telephone calls, and GDPR consent requirements for EU recipients. The consent mechanism is tied to a specific form submission action rather than a standalone opt-in checkbox....
-
StockX
· StockX Terms of Use
The Live Shopping Platform is restricted to users located in the United States, and accessing those features constitutes a representation and warranty that the user is located in the US....
Why it matters: This provision restricts the Live Shopping Platform to US-located users and creates a contractual representation by any user who accesses those features, with potential enforcement implications for users who access the platform from outside the US....
-
Whatnot
· Whatnot Terms of Service
Sellers are prohibited from soliciting or accepting payment from buyers outside the platform's payment processing system, and must notify Whatnot of any circumvention attempts, with violations subject to the platform's enforcement provisions....
Why it matters: This provision restricts sellers from conducting off-platform transactions with buyers encountered through Whatnot, which directly limits seller flexibility to operate across channels and creates a reporting obligation for circumvention solicitations that, if not fulfilled, could itself constitute a terms violation....
-
OpenSea
· OpenSea Terms of Service
Users who submit feedback, comments, or suggestions to OpenSea assign all intellectual property rights in that feedback to OpenSea, including patents, copyrights, trademarks, and trade secrets, and OpenSea may use the feedback for any purpose without compensation....
Why it matters: This provision operates as a full IP assignment clause for user feedback, transferring all rights including potential patent rights to OpenSea without compensation. Unlike the general content license, this clause asserts ownership transfer rather than a license grant....
-
Thomson Reuters
· Thomson Reuters Terms
The agreement states that the site and all its content are provided without any express or implied warranties, and that users assume sole risk for their use of the site and its information, content, and materials....
Why it matters: This provision disclaims all warranties, including implied warranties that might otherwise arise under applicable law, and places the entirety of use risk on the user. Applicable law in certain jurisdictions may limit the enforceability of broad warranty disclaimers, particularly for consumer-facing services....
-
Thomson Reuters
· Thomson Reuters Terms
The agreement states that site content and services do not constitute legal advice, that no attorney-client relationship is formed through site use, and that users assume all risk associated with use of site information and services....
Why it matters: This provision explicitly negates any professional advisory relationship arising from site use, which is operationally significant given that Thomson Reuters markets AI-assisted legal research and drafting products through this site. The disclaimer applies to site content and services as described, though its interaction with separately licensed professional software products may require evaluation under those products' specific terms....
-
Thomson Reuters
· Thomson Reuters Terms
The agreement states that visiting the site or sending emails constitutes consent to receive electronic communications from Thomson Reuters, and that electronic communications satisfy any legal writing requirement applicable to agreements, notices, and disclosures....
Why it matters: This provision establishes that notices posted to the site or sent by email satisfy legal writing requirements, which directly supports the unilateral amendment clause by establishing that posted term updates constitute legally sufficient written notice under the agreement....
-
Thomson Reuters
· Thomson Reuters Terms
The agreement identifies certain site content as forward-looking statements, cautions against reliance on such statements, and discloses that Thomson Reuters files risk factor disclosures with both Canadian securities regulators and the U.S. Securities and Exchange Commission....
Why it matters: This provision reflects Thomson Reuters' status as a dual-listed public company subject to securities disclosure obligations in both Canada and the U.S. The disclaimer is standard boilerplate required for investor-facing communications under applicable securities law and does not create specific consumer obligations....
-
Suno
· Suno Acceptable Use Policy
The page states that free users may generate up to ten songs per day at no cost and without a subscription, described as a permanent free tier....
Why it matters: The 'free forever' characterization sets an expectation of ongoing free access, but the binding terms governing modification, discontinuation, or changes to the free tier are established in the Terms of Service, which was not submitted for review....
-
Figma
· Figma Privacy Policy
Figma certifies compliance with the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. DPF, and commits to resolve DPF-related complaints within 45 days, with unresolved complaints referred to JAMS at no cost to the complainant....
Why it matters: This provision establishes a defined complaint and dispute resolution pathway for EU, UK, and Swiss residents regarding personal data handling, with the DPF Principles taking precedence over conflicting policy terms and binding arbitration available as a final recourse under the DPF framework....
-
Figma
· Figma Privacy Policy
The policy states that Figma does not respond to Do Not Track signals but does recognize and process Global Privacy Control signals, treating them as opt-out requests from the sale or sharing of personal information for targeted advertising under CCPA definitions, with a secondary opt-out available via the 'Manage Cookies' footer link....
Why it matters: This provision establishes Figma's treatment of browser-based privacy signals under CCPA, providing a mechanism through which California consumers may exercise opt-out rights without navigating a separate settings page, though the policy conditions recognition on the ability to 'reasonably associate' the GPC signal with an identifiable consumer....
-
Figma
· Figma Privacy Policy
The policy states that personal information is retained for the duration of service use or as necessary for enumerated business and legal purposes, with deletion or anonymization upon cessation of legitimate need, though data in backup archives may be retained in isolated storage until deletion is practicable; deletion requests require account deletion....
Why it matters: This provision establishes that exercising a deletion right requires deleting the user's Figma account, creating an operational dependency between privacy rights exercise and platform access, and that data in backup archives may persist in isolated storage beyond the user's active account period....