Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
Anyscale · Anyscale Privacy Policy
Because Anyscale reserves the right to change its data practices without explicit prior consent and with only a website posting as mandatory notice, users may not realize their data rights have changed until after new practices are already in effect.
CA-P-010120 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
SoFi · SoFi Privacy Notice
The mechanism creates a conditional user flow for privacy preference management based on authentication status, allowing SoFi to direct authenticated and unauthenticated users to potentially different consent management or preference-setting experiences through the OneTrust platform.
CA-P-009774 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
Geico · Geico Terms of Use
Because the Privacy Policy is incorporated by reference rather than reproduced, users must consult a separate document to understand what data GEICO collects, how it is used, and what rights they have. The terms also state that AI Virtual Assistant inputs may be used consistent with that policy.
CA-P-005059 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
Datadog · Datadog Privacy Policy
This clause establishes the mechanism and timeline for privacy policy modifications, defining how the entity will communicate changes to users and setting expectations for user awareness of evolving data practices.
CA-P-004909 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Substack · Substack Privacy Policy
The one-month response commitment, newly added in this policy update, gives users a concrete service level expectation for privacy rights requests, which is aligned with GDPR Article 12 requirements and provides an enforceable benchmark for EU users.
CA-P-010313 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
Substack · Substack Privacy Policy
This provision establishes the procedural framework for user privacy rights requests, with a one-month response commitment added in the May 2026 update. The provision conditions the availability and scope of rights on applicable local law, meaning the rights available to a given user depend on their jurisdiction.
CA-P-013036 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
Substack · Substack Privacy Policy
The provision establishes procedural obligations for Substack's handling of privacy rights requests and creates a documented timeline mechanism for request fulfillment. It operationalizes user objection rights to legitimate interest processing and requires transparency when processing timelines are extended.
CA-P-006888 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Shein · Shein Terms and Conditions
This provision establishes the technical scope of the consent management layer governing which storage mechanisms are subject to clearing and interception upon consent withdrawal or modification. The decision to intercept document cookies but not localStorage has operational implications for how thoroughly user identifiers are removed upon opt-out or consent changes.
CA-P-012407 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
PayPal · PayPal Privacy Statement
This provision conditions advance notice of privacy policy changes on whether applicable law requires it, meaning that in jurisdictions or for changes where no legal notice obligation applies, the updated terms may become effective without individual notification to users.
CA-P-007904 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Khan Academy · Khan Academy Privacy Policy
This is a meaningful protection for child users that goes beyond minimum COPPA requirements; it confirms that the free educational platform does not monetize children's data through behavioral advertising, which is a common concern with free consumer services.
CA-P-010270 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Salesforce · Salesforce Privacy Statement
The inclusion of 'to prospect sales leads' as an explicit processing purpose means Salesforce may use personal data collected from website visits or other interactions to target individuals as potential customers, which some users may not anticipate.
CA-P-007224 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Windsurf · Windsurf Security & Data Handling
This provision establishes that data transmission to Windsurf servers occurs continuously during IDE use, not only in response to explicit user actions. Compliance teams assessing network traffic, data minimization, and consent requirements should account for this continuous background data transmission in their assessments.
CA-P-013138 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
RunPod · RunPod Privacy Policy
Referral programs can involve sharing of personal identifiers between users or with third-party referral tracking systems, which may not be obvious to participants.
CA-P-009104 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
ADP · ADP Privacy Statement
The layered supplement structure means that the applicable privacy terms for any given user depend on their jurisdiction, and the global policy alone does not constitute a complete disclosure of rights and obligations for users in regulated jurisdictions such as the EU, UK, Canada, or California.
CA-P-012835 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Leonardo AI · Leonardo AI Privacy Policy
Knowing your data rights is essential for controlling how your personal information is used, and the existence of regional-specific rights means the protections available to you depend significantly on where you are located.
CA-P-007583 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Twilio · Twilio Privacy Notice
The availability of region-specific privacy notice versions indicates Twilio has structured its privacy disclosures to address jurisdictional variation, which is relevant for assessing the adequacy of disclosures to users in different markets, including Japan (Act on the Protection of Personal Information) and US/EU markets.
CA-P-012282 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
ElevenLabs · ElevenLabs Usage Policy
This provision establishes that ElevenLabs will disclose user data to authorities when legally required or permitted, which is relevant to users' understanding of the privacy expectations associated with their platform activity.
CA-P-010716 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
GitHub · GitHub Copilot Business Privacy Statement
The access-restricted nature of bridge letters and detailed audit reports means enterprise customers must submit a formal access request before reviewing documents that may be critical to their compliance assessment timelines.
CA-P-011450 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Wix · Wix Privacy Policy
Open-ended retention language means your data could be held for extended periods, and the absence of specific retention periods makes it harder to predict when your information will be deleted.
CA-P-008903 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Webull · Webull Privacy Policy
The clause creates a procedural mechanism for users to exercise data subject rights recognized under privacy regulations, with no specified response timeline, fee structure, or approval conditions stated in the clause itself.
CA-P-000498 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Chase · Chase Privacy Notice
While Chase describes security safeguards at a high level, the policy does not commit to specific technical standards or breach notification timelines, which are common in more detailed security disclosures.
CA-P-008781 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Cohere · Cohere Enterprise Data Commitments
Security certifications provide independent third-party validation that a vendor's data security practices meet defined standards. For enterprise customers, particularly in regulated industries, verifying these certifications is a standard component of vendor due diligence.
CA-P-011334 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI API Data Usage Policies
This provision discloses the security assurance framework applicable to enterprise data, which is a standard due diligence reference point for vendor security assessments and regulatory compliance programs requiring documented technical safeguards.
CA-P-012355 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Asana · Asana Privacy Statement
Security certifications provide some assurance that Asana's data protection practices meet recognized standards, but they do not guarantee that no breaches will occur and do not expand individual legal rights.
CA-P-009990 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
OpenRouter · OpenRouter Privacy Policy
The policy disclaims absolute security guarantees for personal data, which is standard industry language, but means users should not rely on this policy as a contractual security commitment in the event of a data breach.
CA-P-011906 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
TransUnion · TransUnion Privacy Policy
A security freeze is one of the most effective tools to prevent identity theft using your credit data, and placing one is free and can be done online.
CA-P-006198 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Datadog · Datadog Privacy Policy
The policy expressly disclaims any guarantee of security, which is a standard industry disclaimer; users should understand that no absolute protection against data breaches is promised.
CA-P-011206 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Webull · Webull Privacy Policy
The use of 'reasonable measures' without specifying technical standards means the policy does not commit to any particular security framework, which is relevant given the sensitivity of financial and identity data held.
CA-P-010189 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Sourcegraph Cody · Sourcegraph Privacy Policy
This provision establishes a policy-level commitment not to collect sensitive data categories, but the qualifier 'intentionally' means that if such data is inadvertently submitted through code repositories or prompts, the policy does not guarantee it will not be processed.
CA-P-011847 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Zillow · Zillow Privacy Notice
This provision establishes a consent-based data sharing mechanism with real estate professionals that is operationally central to Zillow's business model and relevant to users' expectations about who receives their contact and transaction inquiry information.
CA-P-012471 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial