Provision Registry

12505 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Salesforce · Salesforce Privacy Statement
This provision establishes Salesforce's legal framework for cross-border data transfers from European jurisdictions to the United States, creating accountability mechanisms through DPF certification that include liability for onward transfers to third parties. The certification satisfies regulatory requirements under EU and UK data protection law that would otherwise restrict such transfers.
CA-P-001095 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
YouTube Kids · YouTube Kids Privacy Notice
The clause establishes the scope of permissible data processing activities internal to the service, defining operational functions that rely on information collection and use within YouTube Kids' systems.
CA-P-000566 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
low Privacy rights
Replit · Replit Privacy Policy
The absence of specific retention periods for different data categories means users cannot readily assess how long their code, prompts, usage data, or account information will be retained, which is relevant to data minimization requirements under GDPR.
CA-P-004431 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
low Data retention
Slack · Slack Privacy Policy
This provision establishes the operational framework for data retention lifecycle management, distinguishing between Customer Data (subject to customer-directed retention controls) and Other Information (retained under Slack's discretionary criteria). The provision clarifies that retention obligations are conditioned on both contractual terms and applicable law, and that control mechanisms vary by service tier.
CA-P-001021 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
low Privacy rights
Microsoft Azure · Microsoft Privacy
Because retention periods vary significantly by data type and product and are not fixed, users cannot determine with certainty how long specific categories of their personal data will be held by Microsoft.
CA-P-007947 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Twilio · Twilio Privacy Notice
The notice does not state specific retention periods for most categories of personal data, meaning data collected from website visits and marketing interactions may be retained for extended periods at Twilio's discretion.
CA-P-001332 First tracked Apr 3, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Waze · Waze Privacy Policy
This provision asserts a purpose-based retention standard without specifying concrete retention periods for particular data types such as location history or driving behavior records, which limits users' ability to assess how long their data is held.
CA-P-010891 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Databricks · Databricks Privacy Notice
Open-ended retention language means your data could be kept indefinitely for broad purposes including legal defense, which may conflict with data minimization principles under GDPR and similar frameworks.
CA-P-006114 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Data retention
Threads · Threads Privacy Policy
This clause establishes the legal basis for Threads' data retention practices and defines the retention scope by functional utility rather than explicit time limits. It authorizes retention of both directly provided data and inferred usage information as long as service delivery requires it.
CA-P-008589 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
low Privacy rights
Eventbrite · Eventbrite Privacy Policy
The absence of specific retention periods for most data categories means users cannot easily determine how long their personal information is held, limiting their ability to make informed decisions about their data.
CA-P-008243 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Notion · Notion Privacy Policy
The retention provision uses open-ended language ('as long as we reasonably need it') without specifying retention periods for different data categories, which creates uncertainty about how long specific types of data such as usage logs, deleted content, or account information are held.
CA-P-011198 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Skillshare · Skillshare Privacy Policy
The retention clause does not specify fixed retention periods for any category of personal data, which may engage GDPR's storage limitation principle requiring that data not be kept longer than necessary for the specified purpose; the absence of defined retention schedules may be a point of inquiry for EU and UK supervisory authorities.
CA-P-007052 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Walmart · Walmart Privacy Notice
Open-ended retention language keyed to business purpose rather than fixed time limits provides limited consumer visibility into how long specific data categories are retained, which is relevant to consumer deletion rights and data minimization obligations under applicable state privacy laws.
CA-P-002998 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Medium · Medium Privacy Policy
The absence of defined retention periods for specific data categories may present a compliance consideration under GDPR's storage limitation principle, which requires that personal data be kept no longer than necessary for the specified processing purpose.
CA-P-012728 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Zendesk · Zendesk Privacy Policy
This provision establishes Zendesk's stated data retention framework, which engages GDPR Article 5(1)(e) storage limitation requirements and equivalent principles under other regional frameworks, and is relevant for organizations assessing vendor data lifecycle management practices.
CA-P-012593 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Cohere · Cohere Privacy Policy
The absence of specific retention periods means personal data including submitted inputs, account data, and usage data may be retained indefinitely as long as the account is active or legal obligations require it, without a fixed deletion timeline.
CA-P-004380 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Steam · Steam Privacy Policy
The policy does not specify fixed retention periods for most data categories, meaning your data may be retained for extended periods based on Valve's internal assessments of operational and legal necessity.
CA-P-009907 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Data retention
Pinterest · Pinterest Privacy Policy
The clause defines the operational framework governing data lifecycle management, establishing both the primary retention period (service delivery and policy purposes) and extended retention categories (legal and regulatory obligations). This structure creates distinct retention pathways based on regulatory status and business necessity rather than user discretion.
CA-P-010365 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
low Privacy rights
Gusto · Gusto Privacy Policy
Without specific retention periods disclosed for sensitive data categories like SSNs and bank account information, users cannot easily assess how long their most sensitive data remains in Gusto's systems.
CA-P-003672 First tracked Apr 28, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Disney+ · Disney Privacy Policy
The policy does not specify fixed retention periods for most data categories, meaning data could be retained for extended periods based on broadly defined business needs, which affects the practical value of deletion rights.
CA-P-009496 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
NVIDIA NIM · NVIDIA Privacy Policy
The policy does not specify defined retention periods for most categories of personal data, instead relying on a purpose-based standard; this approach may require evaluation under GDPR's storage limitation principle and equivalent requirements in other jurisdictions.
CA-P-011887 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Square · Square Privacy Notice
Open-ended retention language means your data could be held indefinitely under broad regulatory compliance justifications, limiting the practical effectiveness of deletion requests.
CA-P-010458 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Whatnot · Whatnot Privacy Policy
The absence of specific retention periods means your personal data, including purchase history and financial information, may be held indefinitely under broad business or legal justifications.
CA-P-007070 First tracked May 8, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
RapidAPI · RapidAPI Privacy Policy
The absence of specific retention periods makes it difficult for users to know how long their data is held, and GDPR requires organizations to define and communicate retention periods with greater specificity than this clause provides.
CA-P-004598 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Afterpay · Afterpay Privacy Policy
Knowing how long Afterpay retains your financial transaction history, account data, and behavioral information matters because longer retention periods mean your data remains available for use, sharing, or potential breach exposure for extended periods.
CA-P-005558 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Ideogram · Ideogram Privacy Policy
The absence of specific retention periods makes it difficult for users to know how long their prompts, images, and account data are stored, and creates compliance ambiguity under GDPR's data minimization and storage limitation principles.
CA-P-004448 First tracked May 2, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Figma · Figma Privacy Policy
The retention standard of 'as long as necessary' is broad and gives Figma significant discretion over how long your data, including design file content, is kept after you stop using the service.
CA-P-006779 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Auth0 · Auth0 Privacy Policy
The absence of specific retention periods for most data categories means users cannot easily determine how long their information is kept or plan deletion requests around a known timeline.
CA-P-006482 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Amplitude · Amplitude Privacy Notice
This provision establishes Amplitude's data retention framework but does not specify retention periods for particular categories of data, which may be relevant to GDPR Article 5(1)(e)'s storage limitation principle and to CCPA/CPRA's data minimization requirements.
CA-P-006865 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Okta · Okta Privacy Policy
The absence of specific, published retention periods for different data categories may make it harder for individuals to understand how long their data is held and may create compliance questions under GDPR's data minimization and storage limitation principles.
CA-P-005533 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial