Provision Registry

7353 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Medium × Clear all
medium Data retention
ClickUp · ClickUp Privacy Policy
This clause defines the post-termination data lifecycle and establishes the conditions under which ClickUp maintains or removes personal information after an account ends. The provision creates operational categories for retention (legal obligations, legitimate business purposes) and requires deletion or anonymization as the default outcome, subject to law-based exceptions.
CA-P-005180 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Nextdoor · Nextdoor Privacy Policy
This provision establishes the operational framework governing data retention duration and grounds for continued storage post-deletion. The clause ties retention obligations to service delivery needs, regulatory compliance requirements, and contractual enforcement, creating distinct retention categories with different termination triggers.
CA-P-005778 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Zoom · Zoom Privacy Statement
This provision establishes that Zoom does not commit to a fixed retention period for most personal data, instead tying retention to service needs and legal requirements. The carve-out for legitimate business purposes means some data may be retained beyond the period you actively use the service.
CA-P-011093 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
General Motors · GM Privacy Statement
Open-ended retention language means that sensitive data including vehicle location history and driving behavior may be held indefinitely, increasing the risk of exposure and limiting consumers' practical ability to have data deleted.
CA-P-004825 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Target · Target Privacy Policy
Open-ended retention language means Target does not commit to deleting your data after a fixed period, which has practical implications for the scope of data available for advertising, legal discovery, or potential data breaches over time.
CA-P-003626 First tracked Apr 27, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
SimpliSafe · SimpliSafe Privacy Policy
Retention periods determine how long your home security footage, alarm history, and account data remain accessible to SimpliSafe and potentially to third parties including law enforcement, making this a key parameter in your overall privacy risk.
CA-P-007928 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
T-Mobile · T-Mobile Privacy Policy
This provision establishes T-Mobile's operational framework for data lifecycle management, requiring documented retention decisions based on defined criteria rather than indefinite storage. The framework creates institutional constraints on how long customer data remains in active systems.
CA-P-001700 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
TurboTax · TurboTax Privacy Statement
The provision operationalizes TurboTax's retention obligations by establishing a multi-factor standard—service delivery, legal compliance, dispute resolution, and agreement enforcement—rather than fixed retention schedules. This framework permits differentiated retention periods across data categories based on functional necessity.
CA-P-006817 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Uber · Uber Privacy Notice
The clause defines the operational scope and duration of data retention by linking retention periods to specific business and legal purposes rather than establishing fixed retention windows. This establishes Uber's authority to maintain data records across multiple retention categories tied to distinct functional requirements.
CA-P-007348 First tracked May 9, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Equifax · Equifax Privacy Policy
Open-ended retention language means Equifax may hold sensitive personal and financial data for extended periods, and consumers have limited visibility into how long specific data types are retained unless they submit access requests.
CA-P-006954 First tracked May 8, 2026 Last seen May 20, 2026 Compare across platforms →
medium Data retention
X · X Privacy Policy
The retention policy creates operational distinctions across data categories, establishing different lifecycle periods based on information type and legal or business justification, which determines the duration of X's data storage obligations and the timeline for potential data deletion following account termination.
CA-P-009975 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Fastly · Fastly Privacy Policy
Vague retention language without specific time limits makes it difficult for users to predict how long their data will be held or to plan deletion requests effectively. GDPR requires that retention periods be specified or determinable.
CA-P-010407 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Zelle · Zelle Privacy Policy
These retention periods determine how long your personal information, including fraud reports you submitted, remains in Zelle's systems and available for potential disclosure to third parties or law enforcement.
CA-P-008783 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Visa · Visa Privacy Notice
Data retention tied to business and legal obligations creates a framework where retention periods are not fixed or user-controlled, but instead determined by Visa's assessment of regulatory mandates and business operations. This structure places retention duration outside the scope of individual user preferences or requests.
CA-P-000772 First tracked Apr 3, 2026 Last seen Apr 3, 2026 Compare across platforms →
Poshmark · Poshmark Privacy Policy
The clause ties data retention duration to multiple operational justifications rather than a fixed time period, which means retention may extend beyond account closure for specific purposes enumerated in the policy.
CA-P-003755 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
Coinbase · Coinbase Privacy Policy
The provision creates a retention framework tied to dual standards: operational necessity and regulatory compliance. This establishes that data deletion requests may be subject to mandatory retention periods determined by applicable regulatory regimes, limiting the scope of deletion rights under data protection frameworks.
CA-P-002044 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
Coinbase · Coinbase Privacy Policy
The provision creates a dual retention framework: one based on operational necessity and a second based on regulatory mandate. This structure establishes that retention periods are determined partly by Coinbase's business purposes and partly by external legal requirements that may extend beyond the user relationship termination date.
CA-P-002484 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
Zelle · Zelle Privacy Policy
The retention schedule creates distinct operational timeframes for different data classes, with longer retention for B2B institutional relationships compared to consumer browsing data. This structure affects data lifecycle management obligations and the periods during which personal information remains available for service delivery, support, and institutional operations.
CA-P-006025 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Shein · Shein Terms and Conditions
The operational significance is that user-facing data (such as language preferences and cached content) persists on the user's device for an extended period before automatic deletion, reducing the frequency of server requests while maintaining state information across sessions. This mechanism affects the service's performance and the duration of local data retention without requiring user intervention to clear cached information.
CA-P-004817 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
This clause defines the operational distinction between long-term account storage and temporary service-delivery retention. The 72-hour temporary retention applies independently of user Activity preferences, establishing a baseline data handling requirement separate from persistent account-based storage.
CA-P-008615 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
Netflix · Netflix Privacy Statement
The absence of defined retention limits allows Netflix operational flexibility in data management across active accounts, inactive accounts, and regulatory compliance periods, while placing the determination of retention necessity within Netflix's institutional discretion.
CA-P-007608 First tracked May 9, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
OneLogin · OneLogin Privacy Policy
Without fixed retention periods, users cannot know how long their data will be held, which limits their ability to plan for or request deletion of their information.
CA-P-008017 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Equifax · Equifax Privacy Policy
This provision establishes an open-ended retention standard that does not specify maximum retention durations for sensitive data categories such as Social Security numbers, financial account data, or credit history, which may require further evaluation under GDPR's storage limitation principle and CPRA's data minimization requirements.
CA-P-012558 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Medium · Medium Privacy Policy
Without fixed retention periods, your data could be held for an extended time after you stop using Medium, and you may need to actively request deletion to ensure your information is removed.
CA-P-009555 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Meta Ads · Meta Privacy Policy
The absence of fixed, disclosed retention periods for most data categories makes it difficult for users to understand how long their information is held or to exercise time-based deletion rights with certainty.
CA-P-008161 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Netflix · Netflix Privacy Statement
The absence of defined retention timelines creates operational flexibility for Netflix to maintain personal information based on service delivery needs and legal requirements, rather than fixed schedules. This approach permits indefinite retention of data categories where ongoing service provision or legal obligation applies.
CA-P-002184 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
YouTube Ads · Google Privacy Policy
The provision establishes discretionary authority for data retention duration based on internal company assessments of business and legal necessity, rather than fixed schedules or external review procedures. This creates an open-ended retention framework where the specific duration of data storage depends on Google's ongoing evaluation of necessity across multiple operational categories.
CA-P-000133 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Calendly · Calendly Privacy Notice
Without specific retention periods, users and organizations cannot easily predict how long their data remains in Calendly's systems, which complicates data minimization and deletion compliance efforts.
CA-P-009709 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Twilio · Twilio Privacy Notice
The provision grants Twilio operational discretion to determine retention duration based on stated purposes and legal obligations rather than establishing defined retention windows. This approach allows retention to extend across multiple regulatory frameworks and business purposes without preset expiration dates.
CA-P-005596 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Disney+ · Disney Privacy Policy
The clause establishes retention duration based on operational criteria rather than fixed timelines, which means the actual retention period for any given data category remains contingent on Disney+'s assessment of ongoing relationship status, legal requirements, and legal risk considerations.
CA-P-006252 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial