Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
low Privacy rights
Poshmark · Poshmark Terms of Service
Parents should be aware that minors are not permitted to use Poshmark, and any account opened by a minor violates the terms and may be terminated.
CA-P-010450 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Whoop · Whoop Terms of Use
This provision establishes a minimum age requirement of 18 for service access, which is operationally significant given that the service collects continuous physiological data; the restriction also determines COPPA applicability, as the 18-year threshold exceeds COPPA's 13-year threshold.
CA-P-007384 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Udemy · Udemy Terms of Use
This provision establishes Udemy's stated age restriction and shifts responsibility to users and parents to ensure minors do not access the platform, but the terms do not describe active age verification mechanisms.
CA-P-008496 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Skillshare · Skillshare Privacy Policy
This provision establishes Skillshare's stated COPPA-aligned posture for users under 18; as an online learning platform, Skillshare may attract users near the age threshold, and the operational reliability of age verification mechanisms is a material compliance consideration for FTC enforcement under COPPA and related state laws.
CA-P-012874 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Windsurf · Windsurf Privacy Policy
The policy sets the minimum age at 18 rather than 13, which is the threshold under COPPA for many US online services; this higher threshold affects the scope of the company's obligations and represents the stated age baseline for service eligibility.
CA-P-011522 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Google Ads · Google Ads Terms of Service
This provision establishes a tiered age requirement: 16 as the minimum with parental consent, and 18 for the Google Pay app. The clause acknowledges that the minimum legal age may be higher in certain countries, introducing jurisdiction-specific variability.
CA-P-012114 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI Privacy Policy
The policy authorizes unrestricted use and sharing of data described as de-identified or aggregated; the practical scope of this permission depends on whether the de-identification process meets technical and legal standards that prevent re-identification, which the document does not describe in detail.
CA-P-011509 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Wix · Wix Privacy Policy
While de-identification reduces privacy risk, the practical robustness of de-identification methods varies, and regulators in some jurisdictions apply scrutiny to whether data is truly irreversible.
CA-P-008902 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Bank of America · Bank of America Privacy Notice
The clause operationalizes compliance with federal privacy disclosure obligations, establishing the bank's legal duty to provide transparent accounting of data practices and to communicate statutory limitations on consumer opt-out rights regarding information sharing.
CA-P-003321 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
low Privacy rights
Apple App Store · Apple Privacy Policy
Financial transaction data is highly sensitive and its collection by Apple through Apple Pay raises questions about retention, security, and potential use, though Apple's stated policy of not linking Apple Pay data to user identities and excluding it from advertising is a meaningful consumer protection.
CA-P-003233 First tracked Apr 27, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
OpenAI · OpenAI Data Processing Addendum
This provision grants operators an audit right, which is required under GDPR Article 28(3)(h). The practical value of this right depends on what 'reasonable notice' means and whether OpenAI's standard practice is to provide documentation rather than physical inspections, which is common among large cloud providers.
CA-P-011001 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Google Ads · Google Ads Data Processing Terms
This clause satisfies the GDPR Article 28(3)(h) requirement that processor agreements include an audit right. The practical scope and logistics of exercising this right against a large cloud and advertising infrastructure provider may be operationally complex, and advertisers typically rely on third-party audit certifications such as ISO 27001 or SOC 2 reports as a practical substitute.
CA-P-012124 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Mercury · Mercury Privacy Policy
Inferred data creates profiles beyond what you directly provide, meaning Mercury may hold conclusions about your business or personal characteristics that are derived from behavioral signals rather than information you explicitly gave them.
CA-P-009922 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · Privacy Policy (ROW)
This provision authorizes transfer of user personal data, including conversation content, to unknown third-party entities in the event of a corporate transaction, potentially under different privacy terms.
CA-P-011112 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Monday.com · Monday.com Privacy Policy
A corporate acquisition could result in your personal data being transferred to a new company with different privacy practices, and the notice commitment, while helpful, may not provide a meaningful opportunity to prevent the transfer.
CA-P-008745 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Replit · Replit Privacy Policy
This provision authorizes transfer of personal information to a new entity in the event of a business transaction; the notice requirement provides some procedural protection, but the practical ability for users to opt out of the transfer is not specified.
CA-P-011047 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Fiverr · Fiverr Privacy Policy
A business transfer could result in your personal data being controlled by a different company with different privacy practices, without requiring your affirmative consent to the transfer.
CA-P-007434 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Audible · Audible Privacy Notice
This provision reserves the right to transfer personal data to a successor entity in a business transaction without requiring individual user consent, which is a standard commercial clause but has implications for users whose data may be processed by a new entity under different privacy practices.
CA-P-013203 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Dropbox · Dropbox Privacy Policy
A corporate transaction could result in your data moving to a company with different privacy practices, values, or business models, and the notification commitment, while present, does not give you a right to prevent the transfer.
CA-P-008465 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Figma · Figma Privacy Policy
In the event of a corporate acquisition or merger, your Figma account data, design files, and personal information could be transferred to a new company whose privacy practices may differ from Figma's.
CA-P-010186 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Cerebras · Cerebras Privacy Policy
This clause means your personal data could end up with a completely different company under different privacy practices, and unlike some other disclosures, this transfer may occur without your specific consent at the time it happens.
CA-P-009367 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Shopify · Shopify Privacy Policy
The policy reserves the right to transfer all collected personal data to an acquirer in the event of a merger, acquisition, or insolvency proceeding, without requiring individual user consent or providing an opt-out mechanism for this specific transfer.
CA-P-011124 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Starbucks · Starbucks Privacy Policy
These rights are legally enforceable under the CPRA and Washington state law, meaning Starbucks is obligated to respond to qualifying requests, and consumers who exercise these rights cannot be penalized or given worse service as a result.
CA-P-007242 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Zelle · Zelle Privacy Policy
This provision provides California-specific rights for business contacts, reflecting the CPRA's extension of certain rights to B2B personal information, and establishes a manual email-based process for exercising those rights.
CA-P-008787 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Udemy · Udemy Privacy Policy
These rights, backed by California law, give California residents meaningful control over their personal data at Udemy and cannot be waived by the privacy policy terms.
CA-P-010205 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
Craigslist · Craigslist Privacy Policy
This provides California residents with specific, actionable rights over their personal data, backed by California law, with a direct submission mechanism provided in the policy.
CA-P-008252 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Zillow · Zillow Privacy Notice
These rights give California consumers meaningful control over their personal data, including the ability to stop Zillow from sharing home search and contact data with advertisers and partners.
CA-P-007589 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Mercury · Mercury Privacy Policy
These are legally enforceable rights under California law, meaning Mercury is required to honor them within defined response timelines, giving California-based business owners meaningful control over their data.
CA-P-009923 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Affirm · Affirm Privacy Policy
These rights give California residents meaningful control over their financial and behavioral data at Affirm, including the ability to stop data sharing for marketing purposes.
CA-P-008404 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Whatnot · Whatnot Privacy Policy
These rights give California users meaningful control over how Whatnot uses their personal data, including the ability to stop data sharing for advertising purposes and to have their data deleted.
CA-P-010492 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial