Provision Registry

1160 classified provisions across 277 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Professional free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Data collection × Clear all
MyFitnessPal · MyFitnessPal Privacy Policy
When combined with your health and fitness data, behavioral tracking creates a detailed profile that could reveal sensitive health inferences about you — such as weight loss attempts or dietary restrictions — which are then accessible to advertising partners.
CA-P-006172 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
high Data collection
Epic Games · Epic Games Terms of Service
These tools operate at a device level, meaning Epic collects data beyond just your in-game activity, which raises significant privacy concerns about the scope of monitoring.
CA-P-000640 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
eBay · eBay User Agreement
This is a broad consent to surveillance of your communications and automated contact, with significant privacy implications that many users may not fully realize they are agreeing to.
CA-P-001356 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Amazon Marketplace · Amazon Privacy Notice
This cross-site and cross-device tracking builds a detailed behavioral profile used for targeted advertising and is shared with Amazon's extensive advertising network.
CA-P-003241 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
TaskRabbit · TaskRabbit Privacy Policy
Criminal background data is among the most sensitive categories of personal information, and its collection, retention, and potential disclosure to third parties creates significant risks for Taskers if mishandled.
CA-P-000883 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Uber · Uber Privacy Notice
Criminal record data is special category data under GDPR requiring explicit lawful basis, and the use of background check results in automated eligibility decisions creates risk of disproportionate impact on protected classes without adequate transparency about the decision criteria.
CA-P-002472 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
TikTok Ads · TikTok Advertising Terms
Battery status fingerprinting was specifically condemned by EU data protection regulators as a covert tracking method requiring explicit consent — TikTok's active blocking rule suggests prior unlawful collection that may require regulatory disclosure.
CA-P-005232 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
AWS · AWS Privacy Notice
Behavioral advertising involves your browsing history and online activity being collected and analyzed by third-party ad networks — not just AWS — and used to build a profile of you for advertising purposes across the internet.
CA-P-005584 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Gusto · Gusto Privacy Policy
The extensive deployment of third-party advertising trackers — including Facebook Pixel, Google Ads, LinkedIn Insight Tag, Reddit Pixel, Quora, Marketo, ZoomInfo, Invoca, and Quantcast — observed on the Gusto website represents broad sharing of visitor data with advertising networks, which under CPRA constitutes 'sharing' requiring an opt-out mechanism.
CA-P-005697 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Acorns · Acorns Privacy Policy
Session replay tools like Microsoft Clarity can capture sensitive information entered or viewed on screen, including financial data, and transmit it to third-party analytics providers — this goes beyond standard usage analytics.
CA-P-004618 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
OnlyFans · OnlyFans Privacy Policy
On an adult content platform, detailed records of which Creator content you have viewed and searched for are among the most sensitive behavioral records imaginable and could cause serious harm if disclosed.
CA-P-006090 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Thomson Reuters · Thomson Reuters Terms
Session replay technology can capture detailed behavioral data including mouse movements, clicks, and potentially form field interactions, which goes beyond standard analytics; the presence of Facebook tracking also means browsing behavior may be shared with Meta for advertising purposes.
CA-P-009130 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
TransUnion · TransUnion Privacy Policy
TransUnion deploys multiple advertising trackers — including Facebook Pixel, Google Ads, LinkedIn Insight, and Hotjar session recording — even on its privacy policy page, meaning your behavior is tracked by advertisers while you are reading about your privacy rights.
CA-P-006193 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Audible · Audible Privacy Notice
Keystroke and mouse-movement capture goes beyond standard page analytics — it can reconstruct exactly what you typed and how you navigated, raising significant privacy concerns if not properly disclosed and consented to.
CA-P-001570 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
OnlyFans · OnlyFans Privacy Policy
Selfie-based age estimation involves the processing of facial image data, which may qualify as biometric data under certain state laws such as Illinois BIPA, creating significant legal and consent obligations that the policy does not explicitly address.
CA-P-009226 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
Spotify · Spotify Privacy Policy
Collecting facial images and identity documents is among the most sensitive forms of data collection and triggers specific biometric privacy laws in several U.S. states that require written consent and carry statutory damages per violation.
CA-P-003896 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
Snapchat · Snap Privacy Policy
Face and body geometry data is biometric information — in Illinois and several other states it is legally protected and requires explicit written consent and strict retention limits under laws like BIPA.
CA-P-005933 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Eufy · Eufy Privacy Policy
Biometric data — including facial geometry — is among the most sensitive personal data categories because it is permanent and uniquely identifies individuals. Collection without explicit prior consent violates Illinois BIPA and creates significant class action exposure.
CA-P-006283 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Meta Ads · Meta Privacy Policy
Biometric data is among the most sensitive personal data categories — it is permanent and cannot be changed if compromised — and its collection is subject to strict laws in Illinois, Texas, and Washington as well as GDPR Article 9.
CA-P-001937 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
Cash App · Cash App Privacy Policy
Biometric data is among the most sensitive personal information because it cannot be changed if compromised. Several states, including Illinois, have strict laws governing how companies collect, retain, and destroy biometric data.
CA-P-000608 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
Airbnb · Airbnb Privacy Policy
Government ID and biometric data are among the most sensitive categories of personal information — once compromised, they cannot be changed like a password, and their collection is regulated by strict state laws including Illinois BIPA which carries significant penalties.
CA-P-006866 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Fitbit · Fitbit Privacy Policy
This is among the most sensitive personal data a company can collect — it can reveal medical conditions, reproductive health, and daily routines, making robust data protection essential.
CA-P-001448 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Peacock · Peacock Privacy Policy
Biometric data is among the most sensitive personal information that can be collected because it is permanent and uniquely identifies you. Collection at physical venues like theme parks means this applies even to users who primarily think of themselves as streaming subscribers.
CA-P-007979 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
Whoop · Whoop Terms of Use
Biometric and physiological health data is among the most sensitive categories of personal information and, once collected, cannot be changed if misused; understanding how WHOOP uses and shares this data is critical for any user.
CA-P-007379 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Webull · Webull Privacy Policy
Biometric data is uniquely sensitive — unlike a password or account number, your facial recognition data cannot be changed if compromised. Several states have enacted strict laws governing biometric data collection, including Illinois which allows private lawsuits.
CA-P-003963 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
Bumble · Bumble Privacy Policy
Biometric data is among the most sensitive personal information category under both GDPR and multiple US state laws, and its collection by a consumer dating app creates significant legal exposure and personal privacy risk.
CA-P-005747 First tracked May 8, 2026 Last seen May 12, 2026 Compare across platforms →
Anthropic · Anthropic API Usage Policy
This provision explicitly names neural data — a novel and emerging data category — alongside biometrics, signaling heightened protection for data types that are increasingly regulated under state and national law.
CA-P-000115 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Uber · Uber Privacy Notice
Biometric data is among the most sensitive categories of personal information — it cannot be changed if compromised — and its collection by a ride-hailing company creates significant privacy and safety risks.
CA-P-006902 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Revolut · Revolut Privacy Policy
Biometric data such as facial scans or fingerprints is highly sensitive because, unlike passwords or account numbers, it cannot be changed if compromised, making its collection and protection particularly significant.
CA-P-007479 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
X · X Privacy Policy
Biometric data is among the most sensitive personal information that can be collected because it cannot be changed if misused; collection of government ID data also creates significant identity theft risk if breached.
CA-P-009970 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →

Professional Governance Intelligence

Monitor specific governance provisions across platforms.

Professional includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Professional free trial