PayPal.
PayPal handles money, so the data is uniquely sensitive — SSNs, bank accounts, income, biometrics — and they share it with affiliates, partners, merchants, CRAs, fraud bureaus, governments, and "other third parties" §9. They claim they don't "sell" your data, then hide behind Gramm-Leach-Bliley §15.1 to keep doing things CCPA would otherwise stop. Federal law lets you limit some sharing — but not for everyday business, marketing, or joint marketing with banks §15.2. Your face scans live on for 3 years after you close the account §11.1; everything else for 10 years. They train AI on your data §7.5, use automated decisions to cut you off from services §8, and refuse to honor Do Not Track because "many of our services won't function without tracking data" §3.1.
At a glance, honestly.
Eight signals, color-coded. Like a model card for a machine — except the machine is reading your data.
The Privacy Label, honestly.
An Apple-style label for what's collected and a Cranor-style back-of-pack for what they do with it. Every cell links to the exact line in their policy.
The questions, answered.
No legalese. The eight things every visitor actually wants to know — answered the way your most cynical friend would put it.
Do they sell your data?
They say no. Then they share with affiliates, joint-marketing banks, CRAs, ad platforms, and "other third parties." Under Gramm-Leach-Bliley you can't even limit most of it.Are they tracking you on other sites?
Cookies on partner and merchant sites collect device info, browsing history, and inferences. Do Not Track? Refused.Can your data train their AI?
Yes — to "power our Services." No opt-out is mentioned. Plus "Agentic AI Tools" that can act on your behalf.Who can see what you do?
PayPal affiliates · Venmo · Honey · merchants · CRAs · fraud bureaus · payment networks · governments · ad platforms · other PayPal users (by username/email lookup).Can you delete everything?
No. They keep records for ~10 years for AML/bookkeeping, biometrics for 3 years after closure, and "longer where permitted."Do they honor your opt-out?
"We do not respond to DNT settings." Global Privacy Control: not mentioned. CCPA opt-out: not applicable, they claim, because they don't "sell."Special handling for minors?
Services aren't for under 18. They claim they don't knowingly collect minor data — but verification is essentially self-declared age.Been fined for this before?
Yes — $2M settlement with NY DFS (2018), $4.4M CFPB action (2015), and multiple state-AG inquiries over data and credit practices.The receipts, translated.
Five of the worst clauses, lifted verbatim. Strikethroughs are theirs. Marginalia is ours.
Dark patterns spotted.
Tricks the policy and surrounding UX use to make you "consent" without really consenting.
Your rights, by where you live.
Same company, wildly different rights depending on your jurisdiction. Direct links to the specific opt-out / delete / access flows.
- ✓ Right of access
- ✓ Right to correct
- ✓ Right to erasure (subject to AML retention)
- ✓ Right to object to legitimate-interest processing
- ✓ Right to withdraw consent
- ✓ Right to have automated decisions reviewed
- ✓ Right to data portability
- ✓ Right to lodge a complaint with Luxembourg CNPD
Source: §13.2
- ✓ Right to know categories collected
- ✓ Right to request list of third parties
- ✓ Right to correct
- ✓ Right to delete (subject to GLBA/AML carve-outs)
- ✓ No "opt-out of sale" because PayPal claims they don't sell
- ✓ Right to limit sensitive PI use — but PayPal claims an exemption
Source: §15.1
- ✓ Whatever local law forces them to grant
- ✓ ARCO rights in Mexico (Access, Rectification, Cancellation, Opposition, plus portability/restriction)
- ✓ No statutory deletion that overrides AML retention
- ✓ No AI training opt-out
- ✓ DNT not honored anywhere
Source: §15.3
The actual sources.
Every claim above is anchored to a line in the policy we analyzed. Click any section ID to view it in context.
SOURCE: https://www.paypal.com/us/legalhub/privacy-full · POLICY VERSION: 2026-05-06 · SNAPSHOT HASH: auto
- §3.1Our Use of Cookies and Tracking Technologies / Do Not Track"Because many of our services won’t function without tracking data, we do not respond to DNT settings."
- §4.1Notice at Collection — Categories of Personal Information We Collect"Personal identifiers: Such as name, business name, address, phone number, email, IP address, device information, information collected from cookies or other tracking technologies, government-issued identification, signature, and other information necessary to establish an account or profile."
- §4.2Notice at Collection — Biometric data"Biometric data: Such as voice identification, photo identification, or face scans, which we may collect when you consent in the user experience to authenticate you for certain actions related to your account…"
- §4.3Notice at Collection — Sensitive Personal Information"Sensitive Personal Information: Such as Social Security and tax ID number, government-issued and other related identification, bank account and routing numbers, credit and debit card information, financial information, biometric data (as described above), or precise geolocation data, depending on applicable privacy law."
- §4.4Notice at Collection — Inferred data"Inferred data: Such as gender, income, browsing and purchasing habits, creditworthiness, fraud and risk assessment, your preferences and shopping behavior, which we may infer based on your transactions and interactions with our Services, ads and offers or with our Partners and Merchants."
- §5.1How We Use Personal Information — Provide our Services"We may use Personal Information to help you send, receive or request money, initiate a payment, add monetary value to an account, pay a bill, administer your purchases…"
- §5.2How We Use Personal Information — Comply with laws and risk oversight (KYC/AML)"We may use Personal Information to comply with applicable laws and rules (including anti-money laundering (“AML”), bookkeeping laws and rules issued by our designated banks and relevant card networks, and know-your-customer (“KYC”))…"
- §5.3How We Use Personal Information — Market & personalize"We may use Personal Information to provide you offers and rewards, show ads or otherwise personalize your experience…"
- §5.4How We Use Personal Information — Manage your creditworthiness"Pursuant to applicable law, we will use and exchange Personal Information about you with CRAs to assess creditworthiness and product suitability, check your identity, trace and recover debts, and prevent fraud and criminal activity."
- §6.1Geolocation data"Geolocation data: Such as Global Positioning System (“GPS”), which we may collect with your consent if you have an account for financial Services, and IP-based geolocation data during your user experience or based on your mobile application settings."
- §7.5AI and Automated Decision Making — AI training"We may use Personal Information to train our artificial intelligence (AI) models that power our Services and help us deliver more secure, efficient, and personalized services."
- §8.1AI and Automated Decision Making — Automated Decision Making"If we determine that you pose a credit, fraud, money laundering or other risk, we may refuse to provide new services to you, stop providing services you currently use, or place limits or restrictions on the services you use."
- §8.2AI and Automated Decision Making — Agentic AI"PayPal is committed to offering innovative and personalized experiences, and we may, directly or through our trusted partners, provide you with access to Agentic AI Tools (“Agentic AI Tools”). These AI tools are designed to operate with a degree of autonomy, enabling them to perform tasks, make recommendations, and even initiate actions on your behalf, all while learning from your interactions."
- §9.1When and How We Share Personal Information With Others"We disclose your Personal Information with service providers and third parties, including those participating in the payment network, to help us provide Services, protect our customers from risk and fraud, market our products, and comply with legal obligations."
- §9.2Sharing — Authorities"We may disclose Personal Information with authorities if compelled by a subpoena, court order, or similar legal procedure, when necessary to comply with law, or where the disclosure of Personal Information is reasonably necessary to prevent physical harm or financial loss…"
- §9.3Sharing — Personalized Shopping with Merchants"Unless we are required by law to obtain your consent, we disclose Personal Information collected from you after November 27, 2024 (or from earlier if you consent) for personalized shopping experiences in the United States."
- §9.5Sharing — Other third parties / advertising platforms"For example, we disclose Personal Information to advertising platforms, at your direction. … For marketing purposes, we may use third parties to identify and display ads on our Services tailored to your interests and track interactions with these ads."
- §11.1How Long We Store Your Personal Information"Personal Information used for the ongoing relationship between you and PayPal is stored for the duration of the relationship plus a period of 10 years or such period as mandated by any applicable local law once our relationship comes to an end, unless we need to keep it longer to the extent permitted by applicable law… We retain biometric data for as long as needed or permitted given the purpose for which it was collected and no more than 3 years after your account closes, unless otherwise required by applicable law."
- §12.1Whether Children May Use Our Services"The Sites and Services are not directed to children under the age of 18. We do not knowingly collect information, including Personal Information, from children under the age of 18 or other individuals who are not legally allowed to use our Services."
- §13.1Your Data Protection Rights — Deletion / opt-out limits"If you close your PayPal account(s) or profile, delete, or request that we delete Personal Information, we still need to keep some Personal Information as explained in How Long Do We Store Your Personal Information…"
- §13.2Your Data Protection Rights — How you can exercise your rights"Whether you decide to exercise your privacy rights or not, we will not discriminate or deny you services, charge you different prices, or provide you with a different level of service solely for exercising your privacy rights."
- §15.1Disclosures for Individuals in the United States — Sale & Sharing / GLBA"PayPal does not “sell” Personal Information or “share” Personal Information for cross-context behavioral or targeted advertising that is subject to non-exempt practices under comprehensive privacy laws in the United States… Some Personal Information collected, processed, or disclosed by a financial institution are subject to federal laws, such as the Gramm-Leach-Bliley Act."
- §15.2Notice for Consumers of Financial Products and Services (GLBA notice)"For our everyday business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus Yes No"
- §15.3Other jurisdictions & enforcement history"Please see the table below for additional information relevant to your local country/region. You may lodge a complaint with the Supervisory Authority for data protection in your region if permitted under applicable law."