Provision Registry

3805 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: High × Clear all
Home Depot · Home Depot Privacy Policy
Sensitive personal information is subject to the strongest legal protections under state privacy laws, and its collection by a retail company is noteworthy given the breadth of categories disclosed.
CA-P-010165 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Character.AI · Character.ai Privacy Policy
Users of AI chat platforms commonly share personal details in the course of conversation, and this provision acknowledges that sensitive categories of data may be collected through those interactions, with the policy's primary protection being an advisory warning rather than a technical or contractual restriction on collection.
CA-P-010332 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Walmart · Walmart Privacy Policy
The CPRA established specific rights for consumers to limit the use and disclosure of sensitive personal information; the policy's disclosure of sensitive data categories triggers those rights for California residents and creates heightened compliance obligations for Walmart's health and pharmacy data practices.
CA-P-011363 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
TikTok · TikTok Privacy Policy
The clause defines TikTok's operational framework for handling sensitive personal information, specifying that processing occurs within statutory compliance boundaries rather than under blanket contractual authorization. It establishes user control over the submission of sensitive information as a procedural matter within the service architecture.
CA-P-000301 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Thomson Reuters · Thomson Reuters Privacy
Sensitive personal information carries the highest privacy risk and is subject to the strongest legal protections in most jurisdictions; its collection by a data broker and information products company creates heightened exposure for affected individuals.
CA-P-009350 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Walgreens · Walgreens Privacy Policy
Under CPRA, sensitive personal information is subject to heightened use limitations and consumers have a statutory right to limit its use beyond service delivery. This provision establishes the right but the operational scope of what constitutes service-necessary use for health and pharmacy data in an integrated retail-pharmacy context requires evaluation.
CA-P-012823 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
Grindr · Grindr Privacy Policy
The provision creates a categorical restriction on the use of designated sensitive personal information categories within the entity's AI systems and model training processes, establishing a processing boundary that distinguishes these data elements from other information subject to the privacy policy's AI provisions.
CA-P-001415 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Hinge · Hinge Privacy Policy
Sexual orientation, health, and religious data are among the highest-risk categories of personal information because their exposure can lead to discrimination or harm in certain contexts, and the consent mechanism here is embedded in the act of voluntarily providing the data rather than through a separate explicit consent step.
CA-P-010078 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Microsoft · Responsible AI
The provision operationalizes Microsoft's responsible AI framework by creating a gatekeeping mechanism for high-risk or sensitive use cases. This establishes procedural oversight of application deployment rather than blanket authorization or prohibition.
CA-P-000025 First tracked Apr 3, 2026 Last seen Apr 3, 2026 Compare across platforms →
high Liability limitation
Microsoft · Responsible AI
The provision establishes an institutional framework under which Microsoft designates certain application categories as requiring enhanced governance procedures prior to system deployment. This creates an operational layer of pre-deployment review distinct from standard implementation protocols.
CA-P-002518 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
Airbnb · Airbnb Terms of Service
This provision establishes Airbnb's authority to unilaterally adjust its fee structure and the procedural requirement to provide advance notification. The notice requirement creates an operational framework for fee modifications while preserving the platform's pricing discretion.
CA-P-002759 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
Comcast · Comcast Terms of Service
This provision establishes the operational conditions under which Comcast may discontinue service delivery and specifies that the company retains discretion to terminate service without prior notification. The clause creates a termination authority based on both explicit violation and Comcast's assessment of potential network impact.
CA-P-003786 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
Cursor · Cursor Terms of Service
This provision establishes the operational framework for service availability, specifying that the provider retains unilateral authority to alter service scope and that such changes operate without corresponding liability exposure for the provider. This allocation of modification authority affects the stability and predictability of service access terms.
CA-P-004345 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Replicate · Replicate Terms of Service
The provision establishes Replicate's unilateral authority to alter the service architecture and feature availability without prior notification requirements, and eliminates liability exposure for the company resulting from such modifications or suspensions. This structure concentrates service continuity decisions entirely within Replicate's operational discretion.
CA-P-004301 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Okta · Okta Terms of Service
The clause establishes Okta's authority to unilaterally enforce service access controls based on multiple suspension triggers: contractual violation, legal mandate, or reasonable assessment of security or liability concerns. This operational provision defines the conditions under which service continuity may be interrupted.
CA-P-006660 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Google Maps · Google Maps Platform Terms of Service
The clause establishes Google's operational authority to enforce the Acceptable Use Policy through service suspension as a remedial measure, with a defined notice-and-cure period before suspension takes effect except in legally mandated circumstances.
CA-P-001601 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Duo Security · Duo Terms of Service
This provision establishes Duo's authority to enforce compliance and protect service integrity through suspension and termination mechanisms. The clause permits immediate action without advance cure periods, establishing the operational conditions under which service access may be revoked.
CA-P-004874 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
high Enforcement actions
Google Cloud · Google Cloud Terms
Suspension without prior notice can cause immediate operational disruption for businesses that depend on GCP for production workloads, and the 'risk' standard gives Google significant discretion in making that determination.
CA-P-008430 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Twilio · Twilio Terms of Service
This provision establishes Twilio's authority to discontinue service access unilaterally and instantaneously, without requirement for prior notice or opportunity to cure violations. It grants Twilio broad discretion to determine whether service suspension is warranted based on its own assessment of policy or legal compliance.
CA-P-005931 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
T-Mobile · T-Mobile Terms and Conditions
The clause establishes T-Mobile's operational authority to take suspension and termination actions based on conduct determinations, including a broad catch-all category ('for any other reason'), and specifies that such actions may occur without advance notice to the subscriber.
CA-P-003779 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
Amazon · AWS Acceptable Use Policy
This clause grants AWS unilateral authority to terminate service access without advance notice, which is a material business continuity risk for organizations whose operations, data, or customer-facing services depend on AWS infrastructure.
CA-P-010906 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
high Enforcement actions
AWS · AWS Customer Agreement
An immediate suspension without the opportunity to remediate first could cause significant operational disruption for businesses that depend on AWS for critical workloads, and the triggers for suspension include broad and somewhat subjective criteria such as potential liability to AWS.
CA-P-007744 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Walgreens · Walgreens Privacy Policy
This provision establishes the technical scope of data collection infrastructure deployed across the Walgreens digital platform. The enumerated data categories enable session-level tracking and behavioral analysis through server-side monitoring systems.
CA-P-006369 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Amplitude · Amplitude Privacy Notice
The provision establishes the scope and mechanisms of behavioral tracking conducted through the service, defining which interaction data points are collected and how they are processed. This technical specification determines the extent of user activity monitoring that occurs during service use.
CA-P-006858 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
high Data collection
Skillshare · Skillshare Privacy Policy
The provision establishes the operational framework for continuous activity monitoring and session recording as a standard data collection practice. This mechanism enables the service provider and designated third parties to capture detailed behavioral data for analytics and service optimization purposes.
CA-P-001291 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Stripe · Stripe Terms of Service
The reserve mechanism creates a contractual framework for Stripe to segregate and hold merchant funds as security against post-termination claims, affecting cash flow timing and settlement processes. This operational structure allows Stripe to maintain financial protection while providing defined conditions under which held amounts are released.
CA-P-000751 First tracked Apr 3, 2026 Last seen Apr 3, 2026 Compare across platforms →
Grindr · Grindr Privacy Policy
Sexual orientation is a special category of personal data under GDPR and equivalent frameworks, requiring the highest level of protection. Using or sharing this data for advertising purposes raises significant legal and ethical concerns.
CA-P-009385 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
X · X Privacy Policy
This provision establishes X's operational authority to facilitate data exchange between users and advertisers based on ad engagement signals, while creating a user-controlled mechanism to restrict such sharing. The clause specifies that data sharing serves dual functions: enabling advertiser analytics and supporting X's ad targeting infrastructure.
CA-P-000268 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Square · Square Privacy Notice
Sharing personal data with third-party advertising partners for targeted advertising purposes may qualify as a sale or sharing of personal information under CCPA/CPRA, triggering opt-out rights for California residents, and requires a valid lawful basis under GDPR.
CA-P-010453 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Noom · Noom Privacy Policy
The provision establishes the operational framework for data sharing with external analytics and advertising partners, enabling cross-site data aggregation and analysis. This data practice constitutes a standard mechanism for website analytics and ad targeting infrastructure.
CA-P-001844 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial