Provision Registry

1160 classified provisions across 277 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Professional free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Data collection × Clear all
Acorns · Acorns Privacy Policy
Geolocation data is classified as sensitive personal information under the CPRA, giving California residents specific rights to limit its use, and precise location data can reveal sensitive personal patterns when combined with financial activity data.
CA-P-007367 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Stash · Stash Privacy Policy
Geolocation data collected through a financial app can reveal sensitive patterns about your daily life, routine, and physical location, and its sharing with third-party analytics vendors may extend beyond what users expect when using an investment platform.
CA-P-007864 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Eventbrite · Eventbrite Privacy Policy
Precise geolocation data is among the most sensitive personal data types, and its collection — combined with event attendance records — can reveal sensitive details about your interests, associations, and movements.
CA-P-005252 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Disney+ · Disney+ Privacy Policy
Precise geolocation and persistent device identifiers are among the most sensitive categories of data for advertising and tracking purposes, and their collection by Disney for cross-platform profiling has significant privacy implications.
CA-P-007704 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Hinge · Hinge Privacy Policy
Precise location data is highly sensitive and can reveal sensitive information about your daily routines, home address, workplace, and places of worship. On a dating app, it can also create safety risks if mishandled.
CA-P-001238 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data collection
McDonald's · McDonald's Privacy Policy
Precise geolocation data is among the most sensitive categories of personal information because it can reveal where you live, work, and travel on a regular basis, and this data is used not just operationally but also for advertising.
CA-P-009433 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Robinhood · Robinhood Privacy Policy
Precise geolocation data can reveal sensitive patterns about your physical movements and routines, and its collection by a financial services app may not be expected by most users.
CA-P-008919 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data collection
GOAT · GOAT Privacy Policy
Precise geolocation data is a sensitive category of personal information that can reveal your home, workplace, daily routines, and patterns of movement, and its use for advertising or sharing with partners carries meaningful privacy implications.
CA-P-008263 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Bumble · Bumble Privacy Policy
Precise geolocation data is one of the most sensitive personal data categories because it can reveal where you live, work, worship, and socialize, creating real-world safety and privacy risks for dating app users in particular.
CA-P-001198 First tracked Apr 3, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Venmo · Venmo Privacy Policy
Precise geolocation is classified as sensitive personal information under California's CPRA, meaning California residents have the right to limit its use; for all users, continuous location tracking by a financial app creates a detailed record of physical movements linked to financial activity.
CA-P-009256 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data collection
Redfin · Redfin Privacy Policy
Geolocation data can reveal sensitive information about where you live, work, and spend time, and Redfin uses it both to personalize the service and for broader advertising and targeting purposes.
CA-P-001251 First tracked Apr 3, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
SimpliSafe · SimpliSafe Privacy Policy
Geolocation data reveals your daily movements and home/away patterns, which combined with alarm system activity data creates a detailed behavioral profile tied to your physical residence.
CA-P-007925 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Equifax · Equifax Privacy Policy
Location data can reveal sensitive patterns about where you live, work, seek medical care, or worship, and precise geolocation is classified as sensitive personal information under California law and several other state privacy frameworks.
CA-P-010376 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Walmart · Walmart Privacy Notice
Precise geolocation data is classified as sensitive personal information under CPRA and similar state laws, meaning its collection and use for marketing purposes requires specific disclosure and a mechanism allowing consumers to limit this use beyond service delivery functions.
CA-P-002997 First tracked Apr 18, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Airbnb · Airbnb Privacy Policy
Precise geolocation data is a sensitive category of personal information that can reveal your home address, travel patterns, and daily movements, making it a high-value data type for both personalization and potential misuse.
CA-P-010295 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
Strava · Strava Privacy Policy
Even aggregated or deidentified GPS data, particularly from users who regularly follow distinct routes, can in some cases be re-identified or used to infer sensitive location patterns; this feature has attracted national security and privacy scrutiny in the past.
CA-P-007785 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Arlo · Arlo Terms of Service
Google Analytics data transfers to US servers have been found unlawful under GDPR by multiple EU regulators, and conversion tracking enables Google to link your Arlo purchases to your Google advertising profile.
CA-P-005273 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Arlo · Arlo Privacy Policy
Google Tag Manager acts as a container that can load any number of tracking scripts, including analytics, advertising, and remarketing tags, meaning the full scope of third-party data collection is controlled server-side and may change without visible notice to users.
CA-P-010053 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
Hinge · Hinge Privacy Policy
Government-issued ID contains highly sensitive identity information including your full legal name, date of birth, address, and ID number, and submitting a copy to a third-party app creates risks if that data is not adequately secured or if it is retained longer than necessary.
CA-P-001239 First tracked Apr 3, 2026 Last seen May 12, 2026 Compare across platforms →
Uber · Uber Privacy Notice
Health data is a special category of particularly sensitive personal information under GDPR, and its collection and processing requires explicit consent and heightened security protections — drivers should understand when and why this data is collected.
CA-P-000768 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data collection
Calm · Calm Privacy Policy
This allows a commercial app to access health-related data from your device's health platform, raising questions about how sensitive wellness data is handled and protected.
CA-P-001153 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Calm · Calm Privacy Policy
Sleep data from health apps is sensitive personal information; while Calm states it limits use of this data to its original purpose, users should understand what they are consenting to when granting health app access.
CA-P-009937 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
Strava · Strava Privacy Policy
This commitment offers meaningful protection for sensitive health metrics like heart rate and VO2max collected from wearables, but the carve-out for 'specific purposes described in this Policy' means AI training and service improvement uses may still apply.
CA-P-007783 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Wealthfront · Wealthfront Privacy Policy
Home lending triggers significantly broader data sharing than investment services alone, and your most sensitive financial and personal data flows to underwriters, credit agencies, and servicers over the entire life of the loan.
CA-P-005306 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Netflix · Netflix Privacy Statement
This extends Netflix's data collection into your home network environment, potentially identifying all Netflix-capable devices in your household — a level of surveillance that goes beyond typical streaming service data collection.
CA-P-002622 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
Eufy · Eufy Privacy Policy
A detailed map of your home's interior — including room layout, entry points, and daily patterns — is highly sensitive security and personal data that goes far beyond what consumers typically expect a vacuum cleaner to collect and store.
CA-P-006286 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Coinbase · Coinbase User Agreement
Coinbase collects and retains substantial personal and financial identity information that is shared with regulators on request, and you can be required to provide more documentation at any time or risk account restrictions.
CA-P-007545 First tracked May 9, 2026 Last seen May 11, 2026 Compare across platforms →
Stash · Stash Privacy Policy
Biometric-adjacent data such as facial images used for identity matching may be subject to state biometric privacy laws (e.g., Illinois BIPA) and creates long-term data retention concerns.
CA-P-000532 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data collection
Databricks · Databricks Privacy Notice
Inference data is one of the more sensitive categories under modern privacy law because it represents conclusions drawn about you that you may not be aware of, and which may affect how you are marketed to or evaluated.
CA-P-009271 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
X · X Privacy Policy
Inferred data profiles can be highly sensitive and accurate, yet users have limited visibility into what has been inferred about them and limited ability to correct inaccurate inferences.
CA-P-006639 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →

Professional Governance Intelligence

Monitor specific governance provisions across platforms.

Professional includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Professional free trial