Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
Roblox · Roblox Privacy and Cookie Policy
This provision operationalizes COPPA's data minimization requirement for child users and establishes three specific remedial actions Roblox states it will take upon receiving excess personal information from under-13 users. The provision also reflects the policy's stated commitment to filtering public communications from child users to remove personal information.
CA-P-012367 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Luma AI · Luma AI Terms of Service
This provision establishes age-based access controls and a COPPA compliance commitment. The mechanism for enforcement relies on user self-representation at account creation rather than independent age verification, which is typical but creates a gap between stated policy and practical enforcement.
CA-P-012706 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Xbox · Xbox Terms of Use
Parents are responsible for establishing and managing accounts for younger children, and Microsoft's platform relies on parental consent mechanisms to comply with COPPA and equivalent international laws, meaning parents should actively review and configure Family Safety settings.
CA-P-008280 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Microsoft · Microsoft Services Agreement (Legacy)
This clause implements compliance with the Children's Online Privacy Protection Act (COPPA), which mandates verifiable parental consent before collecting personal information from children under 13. The provision establishes the procedural mechanism by which Microsoft obtains parental authorization before account creation.
CA-P-008421 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Substack · Substack Terms of Use
The minimum age threshold of 16 is higher than COPPA's 13-year statutory minimum, which means Substack has adopted a stricter standard that also captures 13 to 15-year-olds who might otherwise legally use other platforms.
CA-P-007352 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Duolingo · Duolingo Privacy Policy
The policy reserves the right to transfer all user personal data, including learning history, identifiers, and payment information, to a third party in the context of a corporate transaction, without requiring separate user consent at the time of transfer.
CA-P-011283 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Fitbit · Fitbit Privacy Policy
A change in ownership could mean your sensitive health and fitness data, collected under Fitbit's current privacy practices, is governed by a different company's policies, potentially with different sharing and retention practices.
CA-P-009041 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Medium · Medium Privacy Policy
This provision establishes that personal data may be disclosed to prospective acquirers or transaction counterparties prior to deal completion, which creates data exposure outside Medium's direct operational relationships and may engage GDPR requirements for lawful transfer basis during pre-transaction due diligence.
CA-P-012724 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Perplexity AI · Perplexity Privacy Policy
A future acquirer of Perplexity would receive your historical query data and account information, and may operate under a different privacy policy than the one you originally agreed to.
CA-P-010347 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
RunPod · RunPod Privacy Policy
This provision permits transfer of user personal data to third parties as part of corporate transactions, including during the negotiation phase prior to transaction completion, which may occur without direct user notification depending on the transaction structure.
CA-P-013130 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Rumble · Rumble Privacy Policy
This provision establishes that all collected personal data is transferable to acquiring entities without requiring individual user consent beyond notification, which is a standard U.S. commercial practice but may require evaluation under GDPR, Canadian, and other international privacy frameworks depending on the nature and destination of any transfer.
CA-P-012650 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Squarespace · Squarespace Privacy Policy
A change in ownership could result in your personal data being controlled by a different company with different privacy practices, and you may not have advance notice or a meaningful ability to prevent the transfer.
CA-P-010304 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
FanDuel · FanDuel Privacy Policy
This clause means your personal data, including identity documents, payment information, and precise location history, could be transferred to a new owner whose privacy practices may differ from FanDuel's current policy, with no opt-out mechanism described for this scenario.
CA-P-007238 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
OpenAI · OpenAI Privacy Policy
This provision authorizes transfer of personal data during corporate transactions, including during the negotiation phase, without requiring individual user notification prior to the transfer, which may affect the continuity of the privacy protections users accepted.
CA-P-011505 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Pinecone · Pinecone Privacy Policy
This provision authorizes disclosure of personal information to potential and actual acquirers, and separately acknowledges that in insolvency proceedings Pinecone may not be able to control how personal data is treated, which creates uncertainty about downstream data handling.
CA-P-011860 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
OpenRouter · OpenRouter Privacy Policy
The policy authorizes transfer of user personal data, including account information and transaction records, to acquiring or successor entities as part of corporate transactions, without requiring user notification or consent at the time of transfer.
CA-P-011904 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
BeReal · BeReal Privacy Policy
A corporate transaction could result in your personal data being controlled by an entirely different company with different privacy practices, and you may have limited ability to prevent this transfer.
CA-P-009593 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Jasper AI · Jasper Privacy Policy
Personal data could transfer to a different company with potentially different privacy practices in a corporate transaction, and users may have limited ability to prevent this under the terms as stated.
CA-P-010658 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Verizon · Verizon Privacy Policy
CPNI is a legally protected category of telecommunications data; how Verizon uses it for marketing purposes is subject to FCC rules that impose specific consent and opt-out standards distinct from general commercial privacy law.
CA-P-007475 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Verizon · Verizon Privacy Policy
This provision identifies Verizon's obligations as a telecommunications carrier under FCC CPNI rules, which impose sector-specific consent and use restrictions on call detail and network usage data beyond those required by general consumer privacy law. Compliance with these obligations is enforced by the FCC.
CA-P-012999 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
T-Mobile · T-Mobile Terms and Conditions
CPNI includes sensitive call detail records and location-adjacent usage data; without opting out, this data can be used to market additional services to you across T-Mobile's family of companies.
CA-P-008396 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Verizon · Verizon Privacy Policy
CPNI use authorization establishes the operational scope of how telecommunications carriers may leverage call detail records, service usage patterns, and related metadata for commercial purposes within their own marketing operations, subject to regulatory frameworks governing such use.
CA-P-001679 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Privacy rights
T-Mobile · T-Mobile Privacy Policy
CPNI is a federally protected category of information that carriers are generally prohibited from sharing with outside companies without your consent; however, the policy asserts T-Mobile can use it internally for marketing unless you opt out, which is the standard carrier practice under current FCC rules.
CA-P-010242 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Substack · Substack Privacy Policy
This provision establishes a data controller boundary that places responsibility for subscriber data governance on individual Creators when Substack acts as a processor on their behalf. The practical implication is that subscriber privacy rights and data handling practices vary across publications, and Substack's policy does not govern those interactions, which may require subscribers to review multiple separate privacy policies.
CA-P-013035 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
PayPal · PayPal User Agreement
This provision authorizes ongoing credit report access beyond initial account opening, triggered by PayPal's internal risk assessment, which may result in multiple credit inquiries over the life of the account.
CA-P-002282 First tracked Apr 9, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Skillshare · Skillshare Privacy Policy
Cross-border transfers of personal data to countries without equivalent data protection standards create potential risk that your data will be handled under a less protective legal framework than where you live.
CA-P-010481 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Samsung · Samsung Privacy Policy
This provision addresses cross-border data transfers, which engage GDPR adequacy and standard contractual clause requirements for EU/EEA users and analogous frameworks in other jurisdictions. The policy asserts that appropriate safeguards are in place but does not specify the legal transfer mechanisms used.
CA-P-013012 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Airtable · Airtable Privacy Policy
Users in the EU, UK, and other jurisdictions with data export restrictions need to know that their data may be processed in countries with different privacy standards, and that legal safeguards are promised but not specifically named.
CA-P-008272 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
TaskRabbit · TaskRabbit Privacy Policy
This provision frames Canadian user consent to cross-border data transfer as implicit in accepting the privacy policy, which may require evaluation against Canadian privacy legislation governing cross-border transfers and accountability obligations.
CA-P-012513 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Dun & Bradstreet · D&B Privacy Policy
These certifications are the legal basis on which D&B transfers personal data from the EU, UK, and Switzerland to the United States; if a certification lapses or is challenged, the lawfulness of those transfers could be called into question.
CA-P-007991 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial