Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
high Privacy rights
Whoop · Whoop Terms of Use
The agreement discloses collection of a range of physiological and biometric-adjacent data categories on a continuous basis; the handling of this data is governed primarily by the Privacy Policy rather than these Terms, and the Terms incorporate the Privacy Policy by reference without reproducing its data sharing or retention provisions here.
CA-P-012569 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI Enterprise Privacy
A BAA is a legal requirement under HIPAA before a covered entity or business associate can share protected health information with a service provider. The document states this is available for qualifying customers but does not specify which services are HIPAA-eligible, requiring separate confirmation.
CA-P-011971 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
OpenAI · OpenAI Data Processing Addendum
This provision places the compliance burden on the operator to identify when HIPAA applies to their use case and to execute a BAA before submitting any protected health information. Using the API with PHI without a BAA in place would constitute a potential HIPAA violation by the operator.
CA-P-010999 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI Enterprise Privacy
This provision establishes that API-based deployments handling protected health information may be eligible for BAA coverage, which is a prerequisite for using a third-party vendor under HIPAA. The provision specifies API deployments; compliance teams should confirm whether ChatGPT Enterprise or other product tiers are also within scope of the BAA.
CA-P-012446 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Headspace · Headspace Privacy Policy
This classification subjects Headspace to HIPAA's security, privacy, and breach notification requirements as a business associate, establishing a specific regulatory framework for how protected health information is handled. The provision creates institutional obligations for data protection standards and audit/compliance procedures that differ from standard commercial privacy frameworks.
CA-P-001135 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Xfinity · Comcast Privacy Policy
Video footage and sensor data from inside a subscriber's home represent some of the most sensitive categories of personal information, and the policy's scope for using and sharing this data deserves careful consumer attention.
CA-P-007697 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
ADP · ADP Privacy Statement
This provision identifies the specific categories of personal data processed by ADP as a processor, which include payroll, tax, benefits, and HR records, categories that carry heightened sensitivity in some jurisdictions and that trigger specific regulatory obligations regarding accuracy, retention, and security.
CA-P-012834 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
high Privacy rights
Google Gemini · Gemini Apps Privacy Notice
The notice explicitly authorizes human access to conversation content, and the policy advises users not to submit anything they would not want reviewed, signaling that conversation content is not treated as fully private.
CA-P-002310 First tracked Apr 9, 2026 Last seen May 20, 2026 Compare across platforms →
FanDuel · FanDuel Privacy Policy
Government-issued identity documents and tax information are among the most sensitive categories of personal data, and making their submission mandatory means you cannot use those features of the service without providing them, with all associated sharing and retention risks described elsewhere in the policy.
CA-P-007235 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Square · Square Privacy Notice
Biometric data and government-issued identity documents are among the most sensitive categories of personal information, and their collection triggers specific legal obligations in several US states and under GDPR that go beyond standard privacy protections.
CA-P-010454 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Uber · Uber Privacy Notice
Facial image data and government ID copies constitute sensitive personal data in multiple jurisdictions, and facial recognition or matching may qualify as biometric data under laws such as Illinois BIPA, triggering consent requirements and restrictions on retention and sharing.
CA-P-011686 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
Gumroad · Gumroad Terms of Service
This provision authorizes collection of highly sensitive personal and financial data categories, including Social Security Numbers and bank account information, from both Suppliers and Buyers. The data collection is positioned as discretionary rather than universal, but the categories listed represent the most sensitive class of personal identifiers under US and international privacy frameworks.
CA-P-012268 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
high Privacy rights
Plaid · Plaid Terms of Use
This provision establishes a dual-role data use structure in which Plaid acts both as a service provider to developer partners and as an independent data user, creating compliance questions regarding whether downstream independent use is adequately disclosed to consumers at the point of consent.
CA-P-013094 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
Equifax · Equifax Privacy Policy
Inferenced profiles can be used in ways you may not anticipate, including marketing, risk scoring, and product targeting, and may reflect characteristics you have never directly disclosed to Equifax.
CA-P-010374 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
high Privacy rights
PayPal · PayPal Privacy Statement
This provision discloses that PayPal may derive sensitive attributes, including income and creditworthiness estimates, from transaction behavior without requiring separate consent for each inferred attribute, and that these inferences may be used in product recommendations and risk assessments.
CA-P-002337 First tracked Apr 9, 2026 Last seen May 22, 2026 Compare across platforms →
MetaMask · MetaMask Privacy Policy
This provision matters because IP addresses can be used to identify a person's approximate physical location and internet service provider, and when combined with a specific wallet address, can potentially link on-chain financial activity to a real-world identity.
CA-P-007283 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
SoFi · SoFi Privacy Notice
The use of third-party tracking technologies for behavioral advertising may constitute 'sharing' personal information under CCPA/CPRA, and the consent management implementation directly affects whether opt-out signals are properly recognized and applied.
CA-P-011219 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
X · X Terms of Service
This clause establishes the jurisdictional and operational framework for X's data handling practices. By conditioning consent on service use rather than requiring affirmative opt-in, the provision establishes a consent mechanism that applies to all cross-border data transfers conducted by X and its corporate affiliates.
CA-P-007101 First tracked May 9, 2026 Last seen May 9, 2026 Compare across platforms →
Google Ads · Google Ads Data Processing Terms
This clause provides the contractual basis for international data transfers required by Google Ads operations. Advertisers and their legal teams should evaluate whether the Standard Contractual Clauses referenced reflect the current European Commission SCCs adopted in 2021 and whether a transfer impact assessment has been conducted in accordance with EDPB guidance.
CA-P-012121 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
high Privacy rights
LangChain · LangChain Privacy Policy
Personal data of EU, UK, and other non-US users may be transferred to and stored in the United States, which requires an adequate legal transfer mechanism under GDPR and UK GDPR to ensure the data receives equivalent protection.
CA-P-011880 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
GitHub · GitHub Privacy Statement
The policy states GitHub relies on Standard Contractual Clauses for international transfers, which is the standard legal mechanism post-Schrems II; however, adequacy of these transfers depends on supplementary technical and organizational measures that are not detailed in the policy itself.
CA-P-011303 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Xfinity · Comcast Privacy Policy
As your internet service provider, Xfinity has a privileged position to observe your online behavior at the network level, and the policy indicates this data may be used for advertising purposes, which engages both FCC and FTC jurisdiction.
CA-P-007698 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Calendly · Calendly Privacy Notice
Most people assume they only share data with services they have actively signed up for; this provision means Calendly may have your data simply because a colleague or business contact uses the platform.
CA-P-009704 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Calendly · Calendly Terms of Use
Business users who share booking pages publicly are treated as the data controller for all information submitted by meeting invitees, meaning GDPR, CCPA, and other privacy obligations fall on the customer, not Calendly.
CA-P-007681 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
23andMe · 23andMe Privacy Statement
The clause establishes the operational mechanism for research data aggregation and clarifies that participation is not permanent or irrevocable, permitting users to withdraw from the research program prospectively.
CA-P-008861 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
high Privacy rights
Glassdoor · Glassdoor Privacy Policy
Job application data is among the most personal information a user can provide, and its classification as both Sensitive Personal Information and professional data means it carries heightened protection obligations under GDPR and CCPA/CPRA.
CA-P-007149 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Apple · Apple App Store Review Guidelines
This provision prohibits the data collection and advertising practices in child-directed apps that are most commonly associated with privacy risks to minors, including behavioral advertising identifiers, third-party analytics, and social features.
CA-P-011499 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Coinbase · Coinbase Privacy Policy
The policy states disclosure may occur based on Coinbase's good faith belief, not solely on legally compelled orders, and may proceed without notifying the user, which means users may not know when their financial and identity data has been disclosed to government authorities.
CA-P-000416 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
high Privacy rights
TikTok · TikTok Community Guidelines
When law enforcement requests your data, TikTok's guidelines determine what information is disclosed, under what legal standards, and whether you are notified, which directly affects your privacy and legal exposure.
CA-P-009088 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Ring · Ring Privacy Notice
Your home security footage, which may capture activity inside and around your home, can be disclosed to law enforcement without your direct consent in response to legal process.
CA-P-009809 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial