-
Airbnb
· Airbnb Privacy Policy
Airbnb maintains separate privacy supplements for at least seven geographic jurisdictions, indicating that applicable data rights, processing terms, and disclosures vary by the user's country of residence or location....
Why it matters: The existence of jurisdiction-specific supplements indicates that data subject rights (such as access, deletion, portability, and opt-out), lawful processing bases, and data sharing disclosures are defined at the supplement level and are not uniform across Airbnb's user base....
-
Airbnb
· Airbnb Privacy Policy
Airbnb maintains four service-specific privacy supplements covering Airbnb Creators, the Airbnb-friendly Marketplace, Enterprise Customers and Airbnb for Work, and Insurance, indicating that data handling terms differ across these product contexts....
Why it matters: This provision establishes that users of specific Airbnb services are governed by supplement-level privacy terms in addition to the main policy; the applicable processing activities, data categories, and sharing terms for these services are defined in documents not reproduced in this index....
-
Airbnb
· Airbnb Privacy Policy
The privacy framework index includes a reference to a separate Cookie Policy, indicating that tracking technology practices are governed by a distinct document rather than the main Privacy Policy....
Why it matters: The Cookie Policy reference establishes that tracking technology disclosures, consent mechanisms for non-essential cookies, and opt-out procedures for behavioral tracking are addressed in a separate document; users and compliance teams must review that document to assess applicable tracking practices....
-
Visa
· Visa Privacy Notice
The Global Privacy Notice governs Visa's collection, use, and disclosure of Personal Information globally, supplemented by jurisdiction-specific notices and a separate Cookie Notice covering cookies, tags, and similar online data collection....
Why it matters: The operative data processing terms, lawful bases, sharing categories, and retention schedules are distributed across the Global Privacy Notice and at least fifteen regional supplements, meaning no single document contains the complete picture of Visa's data practices applicable to a given user....
-
Visa
· Visa Privacy Notice
Visa publishes jurisdiction-specific supplemental privacy notices for at least twelve regions, stating that these notices provide information required by applicable local law in addition to the Global Privacy Notice....
Why it matters: This provision establishes that users in covered jurisdictions are subject to region-specific privacy terms that may grant rights or impose obligations beyond the Global Privacy Notice, requiring users and compliance teams to consult the applicable regional notice to understand the full scope of their rights....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Visa
· Visa Privacy Notice
Certain Visa products and platforms publish their own privacy notices at sign-up that reflect business-specific requirements applicable to those services, in addition to the Global Privacy Notice....
Why it matters: This provision establishes that the Global Privacy Notice does not necessarily govern all data practices for all Visa products; users of specific platforms are directed to read product-level notices at sign-up to understand the applicable data terms for that service....
-
Visa
· Visa Privacy Notice
Visa maintains a separate Open Banking Privacy Notice applicable in jurisdictions where open banking services are available; users in other regions are redirected to the Global Privacy Notice....
Why it matters: The Open Banking Privacy Notice governs a distinct set of data practices associated with open banking services, which involve access to financial account data and third-party data sharing under regulatory frameworks that differ from standard payment card data processing....
-
Arlo
· Arlo Privacy Policy
The Arlo website footer lists RapidSOS as a named partner, indicating a third-party partnership relationship, but no details of data sharing, service scope, or contractual terms involving RapidSOS are present in the submitted text....
Why it matters: RapidSOS is a platform that routes data to emergency services; its inclusion as an Arlo partner may implicate data sharing provisions involving sensitive location and device data with emergency response infrastructure, which would ordinarily require clear disclosure in the privacy notice....
-
StockX
· StockX Privacy Policy
The policy states that StockX uses third-party session replay technology to record and reproduce user interactions on the site and apps, including mouse movements, clicks, page visits, scrolling, and tapping, for quality control, customer service, fraud prevention, and marketing purposes....
Why it matters: This provision establishes that a comprehensive record of user on-site behavior, including keystroke-level interactions, is captured by a third-party service provider and transferred to and stored by that provider. The use of session replay for marketing purposes, in addition to operational purposes, and the transfer of interaction recordings to a third party may require evaluation under applicable state electronic communications and wiretapping statutes....
-
StockX
· StockX Privacy Policy
The policy states that opting out of data sales and targeted advertising requires completing separate actions in two distinct platform locations: the cookie management portal accessed via the 'Your Privacy Choices' link and the account-level Data Sharing Preferences settings....
Why it matters: This provision establishes that a single opt-out action does not fully effectuate a CCPA 'Do Not Sell or Share My Personal Information' request; users must complete separate actions in both the cookie management portal and account settings. Compliance teams should evaluate whether this two-step mechanism satisfies CCPA opt-out usability and GPC recognition requirements....
-
StockX
· StockX Privacy Policy
The policy states that personal data collected from all users will be processed in the United States, and that for EEA and UK users, transfers rely on European Commission Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms under applicable law....
Why it matters: This provision establishes that all user data is processed in the United States and discloses that EEA and UK transfers rely on Standard Contractual Clauses or equivalent mechanisms. Compliance teams should verify that the SCCs in use reflect current post-Schrems II requirements and that supplementary measures are implemented where the legal framework of the recipient country requires evaluation....
-
StockX
· StockX Privacy Policy
The policy states that when a purchase is made from a seller in the Verified Seller Program, Live Shopping Platform, or Listings Marketplace, personal identifiers, transaction data, and internet or electronic usage data are shared with those individual sellers....
Why it matters: This provision establishes that individual marketplace sellers receive buyer personal identifiers, transaction data, and internet or electronic usage data upon a purchase. Internet or electronic usage data is a category that extends beyond typical shipping and fulfillment data, and the scope of data shared with individual sellers may warrant review relative to user expectations and applicable data minimization requirements....
-
StockX
· StockX Privacy Policy
The policy states that personal data is retained for as long as needed to provide services or fulfill collection purposes, with extensions permitted for legal obligations and dispute resolution, and that aggregate data may be retained indefinitely for research and service development....
Why it matters: This provision does not specify fixed retention periods for any data category, relying instead on purpose-based criteria and a list of factors. The authorization to retain aggregate information beyond stated retention periods for research and development purposes, without a defined timeline, creates an open-ended data retention authorization....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble does not respond to Do Not Track browser signals, and that activating DNT will not affect data collection. The policy separately states that Rumble does recognize and respond to browser-based universal opt-out mechanisms or device-level plug-ins....
Why it matters: This provision establishes that standard browser DNT signals do not alter Rumble's data collection practices, while the policy separately acknowledges recognition of universal opt-out mechanisms. Compliance teams should evaluate whether state laws requiring recognition of universal opt-out signals, such as Colorado's, are satisfied by the stated universal opt-out mechanism recognition....
-
Rumble
· Rumble Privacy Policy
The policy states that Personal Information may be transferred in connection with a merger, acquisition, bankruptcy, or similar transaction, and that users may opt out of such transfer if the successor entity has not committed to maintaining equivalent privacy protections....
Why it matters: This provision establishes a conditional opt-out right for users whose Personal Information is transferred in a business transaction, conditioned on whether the successor entity has committed to equivalent privacy protections. The policy does not specify the mechanism or timeline for exercising this opt-out right....
-
Rumble
· Rumble Privacy Policy
The policy states that EEA/EU, UK, and other users in jurisdictions requiring affirmative consent are not served non-essential cookies until they accept via a cookie banner, and that accepting cookies constitutes consent to collection, processing, and disclosure of all Personal Information gathered through those cookies....
Why it matters: This provision establishes a tiered cookie consent mechanism for EEA/EU and UK users, distinguishing between strictly necessary cookies and non-essential cookies requiring affirmative consent. The policy states that cookie consent is also treated as consent to the processing and disclosure of all Personal Information collected through cookies, which compliance teams may wish to evaluate against GDPR's consent specificity requirements....
-
Rumble
· Rumble Privacy Policy
The policy enumerates California residents' rights under the CCPA to know, delete, correct, and obtain a portable copy of their Personal Information, with specified response timelines of 10 business days for confirmation and 45 days for full response, extendable to 90 days....
Why it matters: This provision establishes the procedural framework for California residents to exercise CCPA rights, including identity verification requirements, authorized agent procedures, and specific response timelines. The policy states that rights requests may be exercised twice per year free of charge and that the right to non-discrimination applies to users who exercise these rights....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble may update or revise the Privacy Policy at any time with or without notice to users, with changes indicated by an updated date at the top of the document, and that more prominent notice may be provided for substantial changes....
Why it matters: This provision reserves the right to modify data collection and processing terms without mandatory prior notice to users, with the date update serving as the sole required indicator of change for non-substantial modifications. Applicable laws in certain jurisdictions may impose notice requirements for material changes to privacy policies that are not fully reflected in this provision....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy authorizes sharing personal information with third-party data brokers, advertising and marketing agencies, analytics providers, and credit agencies that support Thomson Reuters business, as well as with third parties for marketing their own products or services to users....
Why it matters: This provision authorizes disclosure of personal information to data brokers and advertising partners, which in combination with the broad categories of personal information collected including browsing activity, usage history, device identifiers, and inferences from personal information, may engage CCPA/CPRA opt-out rights and analogous state law protections for users in applicable jurisdictions....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy commits Thomson Reuters to refer unresolved DPF-related complaints from EU, UK, and Swiss individuals to JAMS for alternative dispute resolution at no cost to the complainant, with the FTC confirmed as the governing enforcement authority for DPF compliance....
Why it matters: This provision establishes the dispute resolution pathway for EU, UK, and Swiss individuals whose personal data is transferred to the United States under the DPF, including a binding arbitration option as a last resort mechanism under DPF Annex I, and confirms FTC enforcement jurisdiction over Thomson Reuters' DPF adherence....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy describes data subject rights including access, correction, deletion, restriction, objection, portability, and opt-out of profiling and targeted advertising, and provides three submission channels (portal, email, phone), while noting that these rights are subject to exceptions and are only applicable where Thomson Reuters acts as a data controller....
Why it matters: This provision establishes the operational mechanisms for exercising data subject rights but conditions fulfillment on Thomson Reuters acting as a controller for the relevant data, which may limit rights for individuals whose data is processed through Thomson Reuters as a data processor on behalf of enterprise customers. The 2024 California metrics disclose an 87% rejection rate for data access requests and a 51% rejection rate for deletion requests, which may warrant documentation review for compliance adequacy....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses collection of precise geolocation data, device and advertising identifiers, cookie and tracker identifiers, IP addresses, browsing and search history, session replays, and user journey history including clicks, navigation, and user actions....
Why it matters: This provision establishes that Thomson Reuters collects precise geolocation and session replay data in addition to advertising identifiers and behavioral tracking across its Services. Precise geolocation is designated as sensitive personal information under CCPA/CPRA, triggering opt-out rights, and session replay data may engage additional scrutiny under state wiretapping statutes in certain jurisdictions....
-
Kick
· Kick Privacy Policy
The policy states that changes take effect immediately upon posting and apply to previously collected personal information, with continued use of the service treated as acknowledgment of updated terms....
Why it matters: This provision establishes a retroactive update mechanism that asserts changes apply to data already collected at the time of the update, and treats continued platform use as acknowledgment of new terms without requiring affirmative re-consent. The clause includes the qualifier 'to the extent permitted by law,' which acknowledges that applicable legal frameworks may limit the enforceability of retroactive application....
-
Kick
· Kick Privacy Policy
The policy authorizes sharing of hashed email addresses and user IDs with third-party advertising partners and social media platforms including Facebook, Twitter, Instagram, and LinkedIn for cross-device user identification and targeted advertising purposes....
Why it matters: This provision authorizes the transmission of pseudonymized user identifiers to named social media advertising platforms and unnamed advertising partners for cross-device targeting and retargeting. The use of hashed email addresses as cross-device identifiers is a common but regulated practice that may constitute sharing or selling of personal information under certain state privacy laws....
-
Kick
· Kick Privacy Policy
The policy states that age assurance is handled entirely by third-party provider K-ID, with personal information for this process collected directly by K-ID and governed by K-ID's own privacy policy rather than Kick's policy....
Why it matters: This provision establishes that age assurance data is collected and processed by K-ID under K-ID's privacy policy, removing this processing from the scope of Kick's privacy commitments. Users providing information for age assurance are subject to a separate privacy framework that Kick does not control or represent....
-
Kick
· Kick Privacy Policy
The policy authorizes Kick to analyze collected personal information and data from external sources to build interest and preference profiles for advertising targeting, and to use personal information for fraud detection and credit risk assessment....
Why it matters: This provision establishes that Kick conducts profiling of users by combining first-party data with externally sourced data, and applies profiling outputs to advertising and fraud or credit risk assessment. The reference to credit risk assessment is operationally distinct and may engage specific regulatory frameworks depending on how it is implemented....
-
Kick
· Kick Privacy Policy
The policy states that all User Content, including profile information, is posted publicly, and that User Content licenses in the Terms of Service may prevent complete deletion of certain publicly posted information upon request....
Why it matters: This provision establishes that public User Content may not be fully deletable due to license terms in the Terms of Service, which may limit the practical scope of data deletion rights asserted elsewhere in the policy. The interaction between content licensing and data deletion rights is a compliance consideration for jurisdictions where the right to erasure or deletion is a legally established right....
-
Kick
· Kick Privacy Policy
The policy states that personal data is transferred to and stored in countries outside users' jurisdictions, including the United States, and that transfers from the EEA, UK, and Switzerland are conducted under adequacy decisions or standard contractual clauses adopted by the European Commission....
Why it matters: This provision establishes that personal data of EEA, UK, and Swiss users is processed in the United States and other third countries, relying on adequacy decisions or standard contractual clauses as the stated transfer mechanism. The UK's post-Brexit transfer framework and Switzerland's own adequacy assessment framework operate separately from EU GDPR and should be evaluated independently....
-
Kick
· Kick Privacy Policy
The policy states Kick's services are not directed to children under 13, that Kick does not knowingly collect personal information from this age group, and that upon learning of such collection Kick will promptly delete the information....
Why it matters: This provision establishes a COPPA-aligned age threshold and a reactive deletion commitment for data collected from children under 13. The policy relies on the age assurance mechanism (delegated to K-ID) and user self-representation as the primary gatekeeping mechanisms, rather than describing a verified parental consent process....
-
ClickUp
· ClickUp Privacy Policy
The policy states that ClickUp shares user data with third parties for analytics, error tracking, and marketing, and that outside contractors including hosting providers, credit card processors, and mailing list services may access personally identifiable information in the course of providing services to ClickUp....
Why it matters: This provision identifies the categories of third parties that receive user data and the stated purposes for sharing, which are relevant to CCPA sharing definitions and GDPR data processor and controller determinations. The policy requires contractors to protect personal data consistent with the Privacy Policy or Data Protection Addendum and to use it only for contracted purposes....
-
ClickUp
· ClickUp Privacy Policy
The policy states that personal data may be transferred to and processed in countries including the United States, and that continued use of the platform constitutes consent to such international transfers....
Why it matters: This provision asserts that consent to international data transfers is obtained through platform use, which may require evaluation under GDPR Chapter V, which establishes specific lawful transfer mechanisms. The policy defers more detailed transfer safeguards to a separate Data Protection Addendum for contractual customers....
-
ClickUp
· ClickUp Privacy Policy
The policy reserves the right to transfer all user data, including personally identifiable information, to a third party in the event of a business sale, merger, asset transfer, or bankruptcy proceeding, subject to the acquirer agreeing to adhere to the policy's terms....
Why it matters: This provision establishes that user data may be transferred to a new entity following a corporate transaction, with the stated condition that the recipient agrees to the existing policy terms. The practical enforceability of that condition in insolvency or acquisition scenarios may depend on contractual and jurisdictional factors not addressed in the policy....
-
ClickUp
· ClickUp Privacy Policy
The policy states that deletion requests will be honored for actively used databases and readily searchable media, but that copies of personal data may persist in backup systems in a form that is difficult or impossible to locate or remove....
Why it matters: This provision identifies a limitation on deletion request fulfillment, noting that backup copies of personal data may persist after a deletion request is processed. This limitation may require evaluation against GDPR's right to erasure requirements and CCPA deletion obligations, which may recognize technical impossibility exceptions but impose requirements on how such exceptions are documented and communicated....
-
ClickUp
· ClickUp Privacy Policy
The policy requests that users avoid submitting sensitive personal data categories including health information, biometrics, racial or ethnic origin, and criminal background through the service, but states that submission of such data in user-generated content constitutes consent to its processing under the policy....
Why it matters: This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements....
-
Whatnot
· Whatnot Legal Terms
The policy states that personal information is retained for as long as necessary to fulfill collection purposes and meet legal obligations, without specifying fixed retention periods for most data categories....
Why it matters: The absence of defined retention timelines for most data categories may require evaluation under GDPR Article 5(1)(e), which establishes a storage limitation principle requiring that personal data be kept no longer than necessary for specified purposes with defined periods where practicable....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that personal information may be transferred to and processed in the United States and other countries with potentially different data protection standards than the user's country of residence....
Why it matters: Cross-border transfers of personal data from EU and UK residents to the United States require a lawful transfer mechanism under GDPR such as Standard Contractual Clauses or adequacy decisions; the policy's acknowledgment of differing data protection standards is a disclosure obligation but does not confirm that specific transfer mechanisms are in place....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that Whatnot and its third-party partners deploy cookies, pixel tags, web beacons, mobile analytics software, and log files to support service delivery, analytics, and interest-based advertising....
Why it matters: The deployment of non-essential tracking technologies for advertising and analytics purposes requires user consent under the EU ePrivacy Directive and GDPR, and must be implemented through a consent management mechanism that captures freely given, specific, and informed consent prior to activation of non-essential trackers....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that users in certain jurisdictions have rights to access, delete, correct, and receive a portable copy of their personal information, with the specific rights available depending on the user's location....
Why it matters: This provision establishes the framework under which users may exercise regional statutory privacy rights; the practical availability of these rights depends on Whatnot's response procedures, the exceptions asserted in the policy, and the verification requirements imposed on requesters....
-
Whatnot
· Whatnot Legal Terms
The policy states that Whatnot's services are not directed to children under 13 and that Whatnot does not knowingly collect personal information from that age group, with a commitment to delete such data if discovered....
Why it matters: This provision directly implicates the Children's Online Privacy Protection Act (COPPA), which requires verifiable parental consent before collecting personal information from children under 13; the policy's commitment not to knowingly collect such data is the standard COPPA safe harbor formulation, but operational enforcement of age screening is a separate compliance question....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement authorizes Mixpanel to build and continuously update individual behavioral profiles by combining on-platform activity data with third-party business intelligence data, for the purpose of predicting future interest in Mixpanel's services....
Why it matters: This provision authorizes automated, real-time construction of individual profiles using combined first-party behavioral data and third-party enrichment data, which may engage GDPR Article 22 automated processing safeguards and CCPA profiling disclosure requirements depending on the jurisdiction of the user....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement states that Mixpanel may purchase personal data about users from third-party sources including social networks, location service providers, co-brand partners, and public databases, and combines this data with information collected directly....
Why it matters: This provision authorizes external data enrichment through purchase of personal data from social networks and other third-party data sources, which may engage GDPR Article 14 transparency obligations regarding data obtained from sources other than the data subject and CCPA source disclosure requirements....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement reserves Mixpanel's right to derive de-identified data from personal data and to use and disclose that de-identified data to third parties for any purpose, at Mixpanel's sole discretion, subject to applicable law....
Why it matters: This provision asserts broad discretion over the secondary use and third-party disclosure of data derived from personal information, conditioned on de-identification rather than on user consent or specified purpose limitations. The practical scope of this reservation depends on the robustness of the de-identification standard applied and applicable law in relevant jurisdictions....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement discloses that Mixpanel's use of interest-based advertising services may constitute CCPA 'sharing' of Identifiers and Internet or Network Information with advertising partners, from which California residents may opt out; the agreement separately states Mixpanel does not 'sell' Personal Information under the CCPA definition....
Why it matters: This provision operationalizes CCPA opt-out rights for cross-contextual behavioral advertising sharing, including GPC signal compliance, and distinguishes between 'sharing' (disclosed as occurring) and 'selling' (asserted as not occurring) under CCPA definitions. The distinction is legally significant for California residents' opt-out rights and enforcement scope....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement states that Mixpanel relies on the EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework for cross-border personal data transfers from EU, UK, and Switzerland, and accepts ongoing liability for onward transfers to third-party agents that process data inconsistently with the Frameworks....
Why it matters: This provision establishes Mixpanel's cross-border data transfer legal basis and accepts liability for downstream agent non-compliance with Data Privacy Framework Principles, which is a material contractual and regulatory commitment. The provision also states that Framework Principles govern over conflicting Privacy Statement terms, creating a hierarchy of applicable standards....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement discloses that third-party advertising partners deploy cookies and tracking technologies to collect interaction data across browsers and devices, and that Mixpanel may share user information with these partners to enable interest-based advertising on other platforms, including lookalike audience targeting....
Why it matters: This provision authorizes both direct third-party tracker deployment on Mixpanel properties and outbound data sharing with advertising partners for cross-platform and lookalike audience advertising, with the named third-party cookie list including AdRoll, AppNexus, DoubleClick, Facebook, Google, LinkedIn, Twitter, and others....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement grants access, correction, and deletion rights exercisable through Account Settings or by emailing compliance@mixpanel.com, while reserving the right to charge a fee or decline requests deemed unreasonable or excessive, prohibited by law, or where the requester cannot be authenticated....
Why it matters: This provision establishes the procedural mechanism for exercising data subject rights but reserves the right to impose fees or decline requests on grounds that include 'unreasonable or excessive' thresholds, which may require evaluation under GDPR Article 12 and CCPA nondiscrimination provisions in specific jurisdictions....
-
Segment
· Segment Privacy Policy
The notice states that Twilio uses personal data including customer content, communications usage data, and customer support and feedback data to train AI and machine learning models for purposes including security, fraud detection, network optimization, and research and innovation....
Why it matters: This provision establishes that AI and ML training is conducted across multiple stated processing purposes and draws on data categories including customer content such as email bodies, text bodies, media files, and transcripts. Enterprise customers whose contracts govern Twilio's use of customer content as a data processor should evaluate whether the Data Protection Addendum limits or addresses this training use....
-
Segment
· Segment Privacy Policy
The notice states that Twilio may derive aggregated, anonymized, or de-identified data from personal data and use it for any purpose, subject to a stated commitment not to attempt re-identification and to share only with parties bound to maintain de-identification....
Why it matters: This provision authorizes unrestricted use of data derived from personal data once it has been classified as de-identified or anonymized. The scope of this authorization depends on whether de-identification standards applied by Twilio satisfy the thresholds required under applicable law, which varies by jurisdiction....
-
Segment
· Segment Privacy Policy
The notice states that Twilio Inc. and its subsidiary Stytch Inc. are certified under the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, that DPF Principles govern in the event of conflict with the notice, and that Twilio is subject to FTC investigatory and enforcement powers....
Why it matters: This provision establishes the legal framework governing international transfers of personal data from the EU, UK, and Switzerland to Twilio's U.S. operations, and names the FTC as the U.S. enforcement authority. The DPF Principles' priority over the privacy notice in cases of conflict is operationally significant for assessing which obligations govern specific processing activities....
-
Segment
· Segment Privacy Policy
The notice states that Twilio makes real-time automated decisions including account approvals and account suspensions based on fraud and security signals, and that affected individuals will be notified and given an opportunity to object....
Why it matters: This provision establishes that automated decision-making, including account suspension, is performed without prior human review, with notification and objection rights stated to follow the automated decision. The notice separately provides that individuals may contact Twilio to request human review of automated decisions that significantly affect them....