Provision Registry

7353 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Medium × Clear all
Stripe · Stripe Privacy Policy
This definition establishes the scope of information subject to Stripe's data handling practices and retention policies. The broad categorization of Personal Data—including technical identifiers like device information and IP addresses—determines what information falls under the policy's procedural requirements.
CA-P-005374 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Waze · Waze Privacy Policy
The provision grants operational discretion to Waze in determining retention timelines across different data categories, subject to legal compliance and stated purposes. This framework allows the entity to maintain data according to functional necessity rather than fixed deletion schedules.
CA-P-010775 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
Intuit · Intuit Privacy Statement
This provision operationalizes Intuit's data lifecycle management by creating categories of permissible retention periods (purpose-driven, legally-mandated, and claims-related) and establishing a process for eventual deletion or anonymization. The significance lies in the explicit authorization to retain data beyond account closure when legal, accounting, or fraud prevention purposes apply.
CA-P-005471 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Mixpanel · Mixpanel Privacy Statement
The clause conditions data retention duration on subscription tier, creating differentiated data lifecycle management based on customer classification. This operational structure determines the timeframe during which event-level data remains available for analysis and reporting.
CA-P-006893 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
The provision establishes user-controlled data retention parameters, allowing modification of the default 18-month retention period through settings. This mechanism determines the duration Google Gemini retains chat history and associated activity data before automatic purging.
CA-P-001612 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Duolingo · Duolingo Privacy Policy
This clause allocates discretion to Duolingo to determine retention duration based on operational necessity and legal compliance obligations. It establishes a standards-based retention framework rather than specifying defined retention windows, which affects how long user data remains in the company's systems.
CA-P-008882 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Uber · Uber Privacy Notice
This provision establishes that Uber retains discretion to determine the duration and scope of data retention and to decline deletion requests based on broadly stated exceptions including safety and fraud prevention, which are categories not limited to specific statutory retention obligations.
CA-P-012309 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Plaid · Plaid Terms of Use
This provision establishes that disconnecting an application through a partner interface does not automatically result in deletion of financial data from Plaid's systems, and that consumers must take an additional affirmative step through the Plaid portal to request data deletion.
CA-P-013097 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
State Farm · State Farm Privacy Policy
The scope of account deletion is narrower than consumers may expect: deleting your mobile app account does not erase your personal data from State Farm's systems, and the business purpose retention basis is broadly stated without defined time limits.
CA-P-007559 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Coinbase · Coinbase Privacy Policy
This provision operationalizes Coinbase's compliance obligations under anti-money laundering (AML) and know-your-customer (KYC) regulatory frameworks, which require financial institutions to maintain customer identity and transaction records for specified periods to satisfy regulatory reporting and audit requirements.
CA-P-003943 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Amazon Marketplace · Amazon Privacy Notice
The clause defines the operational scope and duration of data retention by establishing multiple grounds for retention: service functionality, stated privacy purposes, legal compliance requirements, and additional communications. This framework governs how long Amazon maintains personal data across different functional categories.
CA-P-003243 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
Stripe · Stripe Privacy Policy
The retention standard ties data persistence to multiple operational categories—service delivery, regulatory compliance, dispute resolution, and agreement enforcement—rather than establishing a fixed retention period. This framework permits extended retention periods when any of these purposes remain active.
CA-P-001881 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
Mistral AI · Mistral AI Privacy Policy
The clause defines the operational duration of data retention and establishes user-initiated deletion as the mechanism for terminating storage. This determines the period during which Mistral AI maintains access to conversation data for service administration and any other authorized uses.
CA-P-004358 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Mistral AI · Mistral AI Privacy Policy
Le Chat conversations do not automatically expire, meaning every prompt and response you have ever sent is retained by Mistral AI until you take action to delete it, which creates a significant accumulating personal data record.
CA-P-010426 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Square · Square Privacy Notice
This clause establishes Square's data retention framework by conditioning storage duration on operational and legal necessities rather than specifying predetermined deletion schedules. This operational approach allows the company to maintain records across multiple compliance and risk management functions simultaneously.
CA-P-001737 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Amazon Marketplace · Amazon Privacy Notice
Without defined retention limits for most categories of personal data, your information may remain in Amazon's systems for extended periods, increasing the potential impact of a data breach and limiting your practical ability to have data fully erased.
CA-P-007523 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Stripe · Stripe Privacy Policy
Data retention for compliance and fraud prevention is standard operational practice in payment processing, as financial services entities are subject to regulatory mandates requiring preservation of transaction records and fraud detection capabilities for specified periods.
CA-P-000745 First tracked Apr 3, 2026 Last seen Apr 3, 2026 Compare across platforms →
Roblox · Roblox Privacy and Cookie Policy
The clause creates a carve-out from full data deletion by permitting extended retention of identifying information beyond account termination, which maintains the entity's ability to track or recognize returning users or devices during the two-year retention window for fraud and abuse prevention.
CA-P-009292 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
Craigslist · Craigslist Privacy Policy
The absence of a specified data retention limit means the company retains operational discretion over retention duration based on stated purposes, rather than a defined schedule or automatic deletion protocol. The security disclaimer establishes that data protection relies on good faith efforts rather than contractual commitments to specific safeguards.
CA-P-003033 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
T-Mobile · T-Mobile Privacy Policy
This provision establishes the operational framework for T-Mobile's data lifecycle management, defining retention periods across multiple service categories and business functions. The clause grounds retention authority in both regulatory compliance obligations and legitimate business operations rather than indefinite retention.
CA-P-006825 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
EA · EA Privacy and Cookie Policy
Open-ended retention standards create operational flexibility for the entity to maintain data archives beyond typical engagement periods, which has implications for the duration users' personal information remains in EA's systems and available for processing.
CA-P-001548 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Data retention
AI21 Labs · AI21 Labs Privacy Policy
The clause creates a retention framework tied to service necessity rather than indefinite storage, establishing operational obligations for data lifecycle management. It specifies procedural requirements—deletion, anonymization, or secure isolation—that govern how personal information transitions from active use to non-operational status.
CA-P-004114 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Privacy rights
DeepL · DeepL Privacy Policy
This provision establishes retention duration in general terms without specifying category-by-category retention periods, which may limit users' ability to assess how long specific data types are held. The reference to legal retention requirements means some data may be retained after account closure.
CA-P-012300 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Adyen · Adyen Privacy Policy
The absence of specific retention periods for most data categories makes it difficult for individuals to know how long their financial and personal data is held, and purpose-based retention can result in extended storage where business or legal purposes are broadly defined.
CA-P-005686 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TransUnion · TransUnion Privacy Policy
There is no fixed maximum retention period for most personal data at TransUnion, and anonymized data derived from your information may be kept and used forever, even if you later request deletion of your identifiable data.
CA-P-009413 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Coinbase · Coinbase Privacy Policy
Because Coinbase is subject to financial regulatory recordkeeping requirements under the Bank Secrecy Act and related rules, certain data including transaction records and identity documents may be retained for five years or more after account closure, limiting the practical effect of deletion requests.
CA-P-011714 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Midjourney · Midjourney Privacy Policy
The policy does not specify fixed retention periods for most data categories, instead using purpose-based retention language; the carve-out allowing extended retention to improve service functionality could cover a broad range of operational activities.
CA-P-000674 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TaskRabbit · TaskRabbit Privacy Policy
The retention provision does not specify defined retention periods for any category of personal information, relying instead on general necessity language, which may require evaluation against GDPR data minimization and storage limitation principles requiring specific, documented retention schedules.
CA-P-005174 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Grubhub · Grubhub Privacy Policy
The additional retention period beyond account closure is not defined by a specific timeframe, meaning your data may be retained for an indeterminate period after you close your account, which limits the practical effect of account deletion.
CA-P-005743 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Lyft · Lyft Privacy Policy
An open-ended retention standard without specific timeframes for each data category makes it difficult for users to know how long sensitive information like location history and trip data is retained, which affects their ability to exercise deletion rights meaningfully.
CA-P-008047 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial