Provision Registry

1160 classified provisions across 277 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Professional free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Data collection × Clear all
medium Data collection
Apple App Store · Apple Privacy Policy
Precise real-time location data is one of the most sensitive categories of personal information because it can reveal where you live, work, worship, seek medical care, and who you associate with. The fact that this data may be shared with partners and licensees extends its reach beyond Apple.
CA-P-002416 First tracked Apr 9, 2026 Last seen May 12, 2026 Compare across platforms →
TikTok · TikTok Privacy Policy
Approximate location is collected by default from IP address and device settings, while precise location collection requires enabling location services; the policy states location services can be disabled in device settings at any time, giving users a direct control mechanism.
CA-P-011619 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data collection
WhatsApp · WhatsApp Privacy Policy
Location data is collected passively and continuously even without explicit user consent to GPS tracking, meaning approximate location is inferred from network data regardless of your location permission settings.
CA-P-009854 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
Teladoc · Teladoc Privacy Policy
Marketo Munchkin creates persistent tracking cookies and associates browsing behavior with known contacts in Teladoc's CRM, meaning a business decision-maker researching telehealth plans for their employees could be identified, profiled, and targeted — and health-adjacent browsing data could become part of that profile.
CA-P-003676 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
WhatsApp · WhatsApp Privacy Policy
Metadata about your communication patterns can reveal sensitive information about your relationships, health, religion, or professional activities even when message content remains private, and this metadata is shared with Meta's broader platform.
CA-P-009851 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
Telegram · Telegram Privacy Policy
Your IP address, which can reveal your approximate location and internet provider, is retained for up to a year and is also the data type that can be disclosed to law enforcement under a judicial order.
CA-P-002915 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data collection
GitHub · GitHub Terms of Service
Parents and guardians should be aware that GitHub collects account data from users as young as 13, and minors using the platform are subject to the same terms and content exposure as adults.
CA-P-001342 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
While Google provides stronger data use protections for minors and students, data is still collected and retained, and the onus is on school administrators to configure appropriate settings — creating a compliance gap for underfunded or under-resourced educational institutions.
CA-P-001918 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
medium Data collection
Netflix · Netflix Privacy Statement
The policy's assertion that Netflix does not knowingly collect personal information from children under 13 engages COPPA obligations; however, the presence of Kids Profile features and the collection of viewing and usage data for profiles associated with child accounts may require evaluation under applicable children's privacy standards.
CA-P-011070 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
Calm · Calm Privacy Policy
Mood and reflection data is among the most personal information a user can share with a wellness app; understanding how this data is stored, used, and potentially shared is important for users trusting Calm with their mental wellness journey.
CA-P-009944 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
Segment · Segment Privacy Policy
Tag management systems can load dozens of downstream tracking pixels and scripts from advertising and analytics partners; the full extent of third-party data collection is determined by the tag container configuration, which is not visible to users from the privacy notice alone.
CA-P-010088 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data collection
Netflix · Netflix Privacy Statement
Gaming data collection is an emerging privacy frontier with limited specific regulation, and Netflix's detailed gameplay tracking creates a behavioral profile that extends significantly beyond video streaming data.
CA-P-002628 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
Netflix · Netflix Privacy Statement
The Netflix Games data collection layer adds device-level identifiers, gameplay behavioral data, and social visibility of certain game data on top of the standard Netflix data collection, expanding the overall data profile Netflix holds about users who play games.
CA-P-000352 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data collection
PayPal · PayPal Privacy Statement
This provision discloses that data collection and the associated Privacy Statement obligations apply even to individuals who have not affirmatively created a PayPal account, and that historical transaction data collected before account creation may be linked to a new account retroactively.
CA-P-002672 First tracked Apr 10, 2026 Last seen May 12, 2026 Compare across platforms →
PayPal · PayPal Privacy Statement
This provision means that people who have never agreed to PayPal's terms of service may still have their personal and transaction data collected, and that data may be retroactively linked to a formal account, expanding PayPal's data profile of that individual.
CA-P-007900 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data collection
Pinterest · Pinterest Privacy Policy
You can have a data profile at Pinterest without ever signing up, which limits your ability to exercise standard account-based privacy controls and raises questions about the adequacy of notice provided to non-users.
CA-P-010361 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
ZipRecruiter · ZipRecruiter Privacy Policy
People who have never interacted with ZipRecruiter may have their professional contact information held and used by the platform without their knowledge or direct consent.
CA-P-008547 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
LinkedIn · LinkedIn Privacy Policy
This provision describes data collection that occurs outside the LinkedIn platform, meaning browsing behavior on third-party websites carrying LinkedIn tracking elements contributes to LinkedIn's profile of your interests and is used for ad targeting and personalization.
CA-P-011347 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
Mistral AI · Mistral AI Data Processing Addendum
The 90-day advance notice requirement, jointly selected auditor, and customer-borne costs collectively create a high practical threshold for exercising on-site audit rights, which may limit their utility as a real-time compliance verification tool. These conditions are notable relative to some enterprise DPA frameworks that impose shorter notice periods or allow customer-selected auditors.
CA-P-010504 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
Revolut · Revolut Privacy Policy
Open Banking access gives Revolut visibility into your full financial picture across multiple institutions, which is more extensive than data collected solely from your Revolut account activity.
CA-P-007673 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Stripe · Stripe Privacy Policy
Millions of people who have never signed up for Stripe may have their data collected and profiled simply by checking out on a merchant website, without realizing Stripe is involved.
CA-P-001875 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
Cloudflare · Cloudflare Privacy Policy
Most people have no idea Cloudflare is collecting their data, because they interact with the website they're visiting, not with Cloudflare directly — yet Cloudflare still processes their personal information.
CA-P-004658 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data collection
Cloudflare · Cloudflare Privacy Policy
Because Cloudflare handles a significant portion of global internet traffic, this passive collection affects an enormous number of people who have no direct relationship with Cloudflare and may be unaware their data is being collected.
CA-P-003011 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data collection
Lyft · Lyft Privacy Policy
Financial data is highly sensitive and its collection and storage by Lyft creates potential exposure if there is a data breach or unauthorized access.
CA-P-000851 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data collection
Fiverr · Fiverr Privacy Policy
Your financial data including billing addresses and transaction history is retained by Fiverr for an unspecified period and shared with payment processing partners, creating potential exposure if those third parties experience a data breach.
CA-P-003442 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
WhatsApp · WhatsApp Privacy Policy
Financial data collection through WhatsApp's payments features introduces a category of sensitive personal information beyond standard messaging metadata, and this data is subject to the same broad Meta sharing framework described elsewhere in the policy.
CA-P-003493 First tracked Apr 27, 2026 Last seen May 11, 2026 Compare across platforms →
Steam · Steam Privacy Policy
Valve acts as an intermediary for your payment data rather than fully delegating to the payment processor, meaning your card details pass through Valve's systems — users should ensure Valve's PCI DSS compliance.
CA-P-006585 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data collection
Fly.io · Fly.io Privacy Policy
While using a third-party payment processor reduces PCI DSS risk, your billing and payment data is still shared with and stored by that third party, introducing additional vendor risk.
CA-P-005362 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Unreal Engine · Epic Games Privacy Policy
Collection and storage of payment card data implicates Payment Card Industry Data Security Standards (PCI DSS) and creates financial fraud risk for users if the data is not adequately secured.
CA-P-000635 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data collection
Fly.io · Fly.io Privacy Policy
Understanding exactly what personal data is collected is the foundation of any privacy rights you may wish to exercise, including deletion or access requests.
CA-P-005357 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →

Professional Governance Intelligence

Monitor specific governance provisions across platforms.

Professional includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Professional free trial