Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
low Privacy rights
Betterment · Betterment Privacy Policy
The absence of specific retention periods for most data categories means Betterment retains broad discretion over how long it holds your sensitive financial information, including after you close your account.
CA-P-009208 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Best Buy · Best Buy Privacy Policy
The policy does not specify fixed retention periods for individual data categories, instead relying on a purpose-based standard, which may make it difficult for consumers to know how long their data is held and may require evaluation under state laws that mandate retention period disclosures.
CA-P-005566 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Auth0 · Auth0 Privacy Policy
The absence of specific retention periods for most data categories means users cannot easily determine how long their information is kept or plan deletion requests around a known timeline.
CA-P-006482 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Waze · Waze Privacy Policy
This provision asserts a purpose-based retention standard without specifying concrete retention periods for particular data types such as location history or driving behavior records, which limits users' ability to assess how long their data is held.
CA-P-010891 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Starbucks · Starbucks Privacy Policy
The absence of specific retention periods for most data categories means consumers have limited visibility into how long their purchase history, location data, and behavioral profiles are kept, which affects the practical scope of deletion rights.
CA-P-004536 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Whatnot · Whatnot Privacy Policy
The absence of specific retention periods means your personal data, including purchase history and financial information, may be held indefinitely under broad business or legal justifications.
CA-P-007070 First tracked May 8, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Canva · Canva Privacy Policy
The policy does not specify defined retention periods for particular data categories, which is relevant to GDPR's data minimization and storage limitation principles and may be a point of inquiry for compliance teams or data subject rights requests.
CA-P-008235 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Afterpay · Afterpay Privacy Policy
Knowing how long Afterpay retains your financial transaction history, account data, and behavioral information matters because longer retention periods mean your data remains available for use, sharing, or potential breach exposure for extended periods.
CA-P-005558 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Leonardo AI · Leonardo AI Privacy Policy
This provision establishes a purpose-based retention framework without specifying fixed retention periods for different data categories, which may affect compliance with GDPR storage limitation requirements and user ability to predict how long their data is held.
CA-P-007584 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Egnyte · Egnyte Privacy Policy
Open-ended retention language based on business necessity rather than fixed timeframes can mean personal data is held for extended periods, which affects deletion rights and security exposure.
CA-P-006403 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Microsoft Azure · Microsoft Privacy
Because retention periods vary significantly by data type and product and are not fixed, users cannot determine with certainty how long specific categories of their personal data will be held by Microsoft.
CA-P-007947 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Twilio · Twilio Privacy Notice
The notice does not state specific retention periods for most categories of personal data, meaning data collected from website visits and marketing interactions may be retained for extended periods at Twilio's discretion.
CA-P-001332 First tracked Apr 3, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
NVIDIA NIM · NVIDIA Privacy Policy
The policy does not specify defined retention periods for most categories of personal data, instead relying on a purpose-based standard; this approach may require evaluation under GDPR's storage limitation principle and equivalent requirements in other jurisdictions.
CA-P-011887 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Eventbrite · Eventbrite Privacy Policy
The absence of specific retention periods for most data categories means users cannot easily determine how long their personal information is held, limiting their ability to make informed decisions about their data.
CA-P-008243 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Gusto · Gusto Privacy Policy
Without specific retention periods disclosed for sensitive data categories like SSNs and bank account information, users cannot easily assess how long their most sensitive data remains in Gusto's systems.
CA-P-003672 First tracked Apr 28, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Replit · Replit Privacy Policy
The absence of specific retention periods for different data categories means users cannot readily assess how long their code, prompts, usage data, or account information will be retained, which is relevant to data minimization requirements under GDPR.
CA-P-004431 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Square · Square Privacy Notice
Open-ended retention language means your data could be held indefinitely under broad regulatory compliance justifications, limiting the practical effectiveness of deletion requests.
CA-P-010458 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Affirm · Affirm Privacy Policy
An open-ended retention standard without specific timelines means your financial and behavioral data may be retained indefinitely unless you affirmatively request deletion.
CA-P-008406 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Brex · Brex Privacy Policy
Open-ended retention tied to legal and regulatory obligations is common in financial services, but it means your data may be held for extended periods beyond your active use of Brex products.
CA-P-009181 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Samsung · Samsung Privacy Policy
Without defined retention periods for specific data types, personal data including browsing history, location, and health metrics may be retained for extended and undefined periods, which limits consumer ability to predict when their data will be deleted.
CA-P-007960 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Chime · Chime Privacy Policy
A deletion request may not result in complete removal of your data if Chime determines it has legal or business reasons to retain certain records, which is a standard but important limitation on the right to deletion.
CA-P-009951 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Sony PlayStation · PlayStation Privacy Policy
The absence of specific data retention periods in the main policy text means users may not know how long their behavioral, communications, or account data is retained, which is relevant to both privacy risk and the exercise of deletion rights.
CA-P-008459 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Rumble · Rumble Privacy Policy
How long your data is kept and where it is stored affects your ability to exercise deletion rights and the risk that your information could be exposed in a data breach.
CA-P-007200 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Anyscale · Anyscale Privacy Policy
The absence of specific retention periods for most data categories means your personal information may be retained indefinitely for broadly stated business purposes, which may be difficult to challenge or verify.
CA-P-010121 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Twitch · Twitch Privacy Notice
Without specific retention periods disclosed, users cannot know how long their data, including sensitive information like billing details and chat history, is held by Twitch.
CA-P-009602 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Garmin · Garmin Privacy Statement
Open-ended retention tied to account activity means your health and location data may be held indefinitely if you remain a Garmin user, and some data may persist even after account deletion due to legal hold or dispute resolution exceptions.
CA-P-010357 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Zendesk · Zendesk Privacy Policy
The notice does not specify concrete retention periods for most data categories, which means the duration Zendesk holds your data is determined by Zendesk's internal policies and legal obligations rather than fixed timelines disclosed to users.
CA-P-005851 First tracked May 8, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Hulu · Hulu Privacy Policy
The absence of specific retention periods means your data may be held indefinitely under broadly defined business or legal purposes, which is a common but notable practice that limits your practical ability to know when your data will be deleted.
CA-P-008175 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Mercury · Mercury Privacy Policy
There is no fixed maximum retention period stated in the policy, meaning some categories of financial and personal data could be held for extended periods tied to legal and regulatory timelines.
CA-P-009924 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Noom · Noom Privacy Policy
Without specific retention periods, users cannot know how long their sensitive health data will be held, making it harder to assess long-term privacy exposure.
CA-P-001846 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial